remove websocketcontroller and let sessioncontroller do the authorization add toString to User entity