In preparation for adding a separate authorization strategy for client requests, I have moved the implementation of the authorization strategy for host requests in to the `server::host` module.