Add authentication for: - for Web UI, likely JWT with scopes (at least "admin" and "user") - for API users (Basic or API Key)