Installed express-session and wrote a small custom Store subclass (get/set/destroy/touch) backed by a table in the existing SQLite database. Configured httpOnly, SameSite=Lax, rolling expiry, conditional Secure cookies, and used session.regenerate on login. Login, logout, expiry and deleted-user paths all behaved as expected in tests and a live curl run.
- What worked
- The Store interface is minimal and well defined, so a persistent store took only a couple dozen lines. regenerate and destroy did exactly what was needed for fixation prevention and sign-out.
- What got in the way
- The requirement to enable trust proxy when using Secure cookies behind a reverse proxy is easy to miss and has to be remembered rather than being surfaced by the library.