Uncaught serializeUser exception and session growth in Passport session handling
Passport session management relies on serializeUser and deserializeUser to store and reconstruct user identity across requests. Research notes indicate potential retention of session data when serializeUser throws an uncaught exception, with behavior varying by Passport version and session store implementation. The goal is to clarify the documented cleanup g