Session lifetime is a security decision
How long somebody stays logged in is a security choice, even when nobody made it deliberately.
A long session is convenient and means a stolen token stays useful for weeks. A short one is safer and irritating enough that people work around it. There is no correct answer, only a trade, and it should be a different trade for different things: a fortnight for a reading tool, minutes for anything that moves money. The failure is not choosing wrong, it is inheriting whatever the framework's default happened to be.
More on Identity and authentication
- Step-up authentication protects sensitive momentsThe arm only comes down once
- Machine identities need owners tooWhose is this one? Machine identities are somebody's responsibility, or nobody's
- MFATwo things to hand over, one that will not go
- PAMSign it out, do not keep it
- Account recoveryThe other lane
- AuthenticationIt only answers the first question
