Set-Cookie: SESSION_ID=abcde12345; Path=/; HttpOnly
Session.find_by(session_id: cookie['SESSION_ID']).user