The access to spectrograms rely on the fact that the user has basic access to the spectrogram file.
In an updated version we use the API to check if they have access to the recordingId, if they have access we allow them to see the recording spectrograms.
The username/email can be used to associate the local annotations with a specific user.