I use the fairly simple Express + Mongoose + Passport + Connect-mongo setup and everything works fine. The only thing that puzzles me is that I see passport.unserializeUser , even called for static files, which - from my point of view of the application - is completely pointless.
I can understand that there are cases when you want static files to be serviced under some kind of authorization, but I am wondering how I could βskipβ all the session middleware if I serve a static file.
(In a production environment, I could not use cookies for assets)
source share