comments (single view)

that literally shows my point, it uses GET to get data about the currently logged in user, which you need a token for in the headers

and it uses POST for auth

View all comments