cover that the created Text carries the supplied User, that the controller persists the user from the session attribute, and that any userId in the request body is ignored.
refactor to setUp as well