headers->get("authorization") != "Bearer abc123") { # TODO: get user based on bearer token throw new UnauthorizedError(); } return new JsonResponse([ "account_data" => [], "next_batch" => "", ]); } }