REST api - set different passwd from root

How does the Arduino luci logic authenticate the REST password? does it sync some separate file akin to a sort of .htaccess that uhhtpd picks up or does it authenticate to the OS with some service provided by LuCI and OpenWRT?

Can the REST password be changed by itself via shell? (I don't care if later gets overriden by Arduino Web Interface).

I think a good feature would be to be able to optionally specify a different password for the REST interface on the Yún configuration screen.

TIA,
Alex