In fact, I want to restrict users from connecting to the Socket before logging into the Web.
For api calls, I can use passport.js(session) and do the following to restric