I am trying to get sessions working on my api.
I want to be able to define certain endpoints as restricted, which would need the user to be logged in to access them.