Session lifetime is a security decision

How long somebody stays logged in is a security choice, even when nobody made it deliberately.

A long session is convenient and means a stolen token stays useful for weeks. A short one is safer and irritating enough that people work around it. There is no correct answer, only a trade, and it should be a different trade for different things: a fortnight for a reading tool, minutes for anything that moves money. The failure is not choosing wrong, it is inheriting whatever the framework's default happened to be.

More on Identity and authentication