Official Business
Going to /robots.txt
reveals the server source code, along with some authentication checks.
We didn't really do this the intended way.
Set the auth cookie to
which is the encoded form of
{'user': 'admin', 'password': 'pass', 'admin': True, 'digest': 'hashlib.sha512(secret_key + bytes(json.dumps(cookie, sort_keys=True), "ascii")).hexdigest()'}
This makes the SHA512 comparison always true, allowing you to log in as the admin.