Instead of using `$_SESSION` global variable there's a need for session container class which we can later extend to support signed cookies.