**Suggested next action**: - [ ] check if user has JWT, add to req - [ ] handle unauthorised user
Suggested next action: