The easiest way would be to start a session when you get a request with a userid, and then assume subsequent requests in the same session are for the same user. When you get another userid, destroy the earlier session and start a new one.
It would be much more reliable, however, to include the userid on all requests. How to do that would likely depend on your scanning device.