Variable
ConstIts middleware verifies the session from the request's own headers and
hands the action ctx.learnerId. That is the only way an action learns who
the learner is: no input schema built on this client may carry a user or
learner id, so a client cannot act for someone else. Without a session the
action body never runs and the caller receives serverError.
The safe-action client for anything that reads or writes one learner's data.