Finished writing api.php file, README, and hook_help callback. The module has the needed functionality to work as intended, and is therefore considered a complete module.
Also set the user password to not be logged under any circumstance.
Previously, in the case of entity reference, the check if the entity was managed (reminder, we exclude users and config entities from sharing) was done on the JSON returned by the JSON API.