Also why would anyone store and read data like { 'groups': [...] } on the client-side?
Session cookies are supposed to be identifiers only, with the data stored server-side.
> This is implemented on top of cookies for you and signs the cookies cryptographically. What this means is that the user could look at the contents of your cookie but not modify it, unless they know the secret key used for signing.
Please stop.
> By default flask doesnt have a db.
Do not trust the data you send to a user, to remain secure.
Security through obscurity is allowing REST commands to the /totallysecretaddress/neverleaked/ URI.