Hi!
First of all, that's a nice project structure! 👍
Just playing with it and discovered that /api/profiles/:username always returns "following": false whether a token is provided or not in the standard Authorization.
Meanwhile, I'll keep looking for the root cause.