remove auth: true and user information will be in ctx.state.user assuming that a JWT was used
ctx.state.user