Token handling
- The controller can than later decide to check if any of the
psgix
values is set, and deny access based on the values stored there.
- This combination of PSGI Middlewares and enhanced HTTP request objects make a lot of problems very easy to solve.