Add password config option
Just as a side note, this is not 100% secure and probably shouldn't even be done on this level.
Administrators can (and should) set up an HTTP auth on reverse proxy level to restrict access