* listing of modules in website already bypassed session user * altered authenticated endpoint so it does the same * sudoed a few read accesses & name_get in groups * other accesses are list/form views, menu only accessible to system_user * new-API-ified some calls & unified listing of installed modules