These accounts are for local development only.
-
Username: administrator
-
Email: administrator@local.dev
-
Password: Admin!23456
-
Role: Admin (
is_admin = 1) -
Username: default_user
-
Email: default_user@local.dev
-
Password: User!23456
-
Role: Player (
is_admin = 0)
- Passwords are intentionally simple enough for local testing.
- Do not use these credentials in production.
- If you need to reset both users quickly, run SQL updates in the
userstable and set a freshpassword_hashvia PHPpassword_hash().
- The login page now includes a local dev password reset tool.
- It calls
POST /api/auth.php?action=dev_reset_password(CSRF protected). - The tool is controlled by
ENABLE_DEV_AUTH_TOOLSinconfig/config.php(enabled by default for non-production). - Rate limit: max 5 reset attempts per 10 minutes per browser session.