now server can create login cookie and client can store cookie in broser. We use userId as token for login cookie for convinence for now.