Handles `GET /v1/control/verification-sessions/{session_id}`.
Errors
Returns 401 without a session, 403 for an API key or a role without
VERIFICATIONS_READ, 404 for a session this tenant does not have -
another tenant’s and a nonexistent one answer alike - and 503 when a
store cannot be reached.
Authorizations
A signed-in reviewer's session. httpOnly and SameSite=Lax; set by POST /v1/control/sessions and only usable once the second factor is met.
Path Parameters
The session id
Response
The session, its checks and its resolved decision
One session in full.
When the session was opened.
When the capture link stops working.
FIRST_TIME or REVERIFICATION.
The session id, which the capture link and the webhook both carry.
PENDING, PASSED, REVIEW_REQUIRED, FAILED or EXPIRED.
The person, as the customer identifies them.
Every required check in policy order, then any that ran unrequired.
The policy version whose checks this session had to satisfy.
Why the decision was what it was, from the decision store, reworded.
When the session concluded. Absent while it is open.
That decision's outcome, read from the decision store.
ALLOW, WARN, BLOCK, HOLD, REVIEW_REQUIRED, FLAG, BLOCK_RECOMMENDED, SUSPEND, END_STREAM The decision the session produced, once it has.
The review case opened for the decision, read from the case store.
That decision's risk level, read from the decision store.
LOW, MEDIUM, HIGH, CRITICAL 
