# Phase 005: Lightweight Internal Authentication ## Goal Implement simple internal identity tracking without passwords. ## Work - Add a monthly access key concept for initial identification. - Add a flow where a person enters/scans the current key, provides name/email, and receives a session. - Store only a session user id/token in the browser after verification. - Add `Current.user` or controller helper methods for accessing the active user. - Require an identified user before creating fuel or maintenance entries. - Keep admin/regular user roles out of scope for now. ## Deliverables - Login/identification page. - Session creation and clearing. - User creation or lookup by email. - Controller specs/request specs for authenticated and unauthenticated flows. ## Acceptance Criteria - Passwords are not used. - Raw QR/monthly key is not required on every request after session creation. - Fuel and maintenance submissions are attributed to the active user. - Unidentified users cannot submit entries.