I am trying to understand the functionality and relevance of the 'secret' option in express-session.
I have already tried browsing online for some information regarding this, but couldn't find anything substantial.
This is what I found on the npm express-session package page: secret
Required option
This is the secret used to sign the session ID cookie. This can be either a string for a single secret, or an array of multiple secrets. If an array of secrets is provided, only the first element will be used to sign the session ID cookie, while all the elements will be considered when verifying the signature in requests.
I don't understand how exactly does secret accomplish signing the session ID cookie. How exactly is this required feature implemented behind the scenes?