Handle API authorisation with hard coded credentials from client

Handle authentication, and authorisation for an api that is visible only for admin user, called from html page Javascript with a hard coded header