Session Inactivity, Expiration and Remember Me Solve Different Problems
A session can have an idle timeout, a hard lifetime and a trusted-browser persistence policy at the same time.
A session can have an idle timeout, a hard lifetime and a trusted-browser persistence policy at the same time.
Long-lived trusted-browser sessions change the authentication risk model and should be chosen deliberately.