Password handling
- TourLedgers uses PBKDF2-SHA256 password hashing with per-user salts.
- Plain text passwords are not stored by the application.
TourLedgers is designed around protected accounts, server-side sessions, D1 data storage, and careful handling of buyer-facing reports.