Is the vision here that eventually I just have ngrok sit in front of my web app server(s) to handle authentication, rather than doing it at the app layer? And then ngrok in theory forwards on headers or whatever info I need for the authenticated users, like a middleware sitting on top?