see more https://www.sohamkamani.com/golang/oauth/ todo [] protect access_token and don't pass it to the client, use sessions table instead