I understand how the process and request flows in passport but what i dont understand is why are we even using a session store when the cookie just expires after the max age but the session in the session store is always there storing the session id even after the cookie is expired!?