Admin
Sessions
When authentication is added, this is where active sessions are listed and
revoked: who, from where, since when, last seen. The place it hooks into the code
is require_admin() in app/admin.py — one function that
every route on this page already depends on.
Until then, treat reachability of this server as full access to it.
