I’ve noticed that the express-session library requires a secret for signing session cookies. How exactly does this secret work to protect against threats like session hijacking or tampering? What are the best practices for generating and managing this secret to ensure robust security?