Settings
API & server info
| Data API base | |
| Play site | https://play.orcsgirls.org |
| Admin panel | https://play.orcsgirls.org/admin/ |
| DB name | ORCSPlay |
Security notes
- Admin access requires HTTP Basic Auth credentials (set via
.htpasswdon the data server). - Class code brute-force is rate-limited to 8 attempts per IP per 5 minutes server-side.
- Quiz join is rate-limited to 20 attempts per IP per 10 minutes.
- Quiz host actions require a session-specific
host_tokengenerated at game start. - Student submissions are content-scanned on insert; inappropriate content is auto-hidden.
- All admin endpoints re-verify Basic Auth credentials in PHP as a defence-in-depth layer.