NOTICKET: Refactor project management API to use auth held in session