We can provide our route security and authentication by forcing parents to go through /parents/:id/readers and /:id. This will keep /readers to admins and front desk only.
Also,
we don't need to rewrite, we can mount readers route on parents route and compound the concerns while still keeping our modules intact.