handle receives the request's event and resolve, which continues to the route and produces its response.
A cookie is untrusted input. Verify the session before assigning locals.user; don't treat a cookie's user ID as proof of identity.
Return resolve(event) after preparing the request data. locals is not automatically sent to the browser.
import { getUserFromSession } from '#lib/server/auth.js';
/** @type {import('@sveltejs/kit/hooks').Handle} */
export async function handle({ event, resolve }) {
const token = event.cookies.get('session');
event.locals.user = await getUserFromSession(token);
return resolve(event);
}