The Shiny session token cannot be read in JavaScript, so the server pushes it
once at session start; the client then stamps it on every queued row (the
session column of ms_log_header()). Call it at the top of the server
function, before any ms_track() call, so no event is written without it.
Details
The token is authoritative, the IP is only a fallback: behind shiny-server
a session sees 127.0.0.1, so an ip already baked into the page by
ga_js() wins and this one is ignored. Without that rule the websocket's
useless address would silently overwrite the good one a moment after the page
supplied it.