Concept Flow - Local strategy (username/password)
User submits username & password
LocalStrategy validate() called
Check username & password in DB
Return user object
Passport attaches user to request
Request proceeds to controller
User sends credentials, LocalStrategy checks them, returns user if valid, else rejects.