Without this, session cookie is not sent with fetch() requests, causing server to redirect to login (returning HTML instead of JSON).