I\'m trying to block access to the admin dashboard itself for non-admin users. For this, I have to check in the back-end if the token is valid and if so, that the user is actual