I still have automatic session renewal on my to-do list, though. As in, you will only be logged-out when you haven‘t logged in for two weeks. But Having to re-log in every two weeks isn‘t that big a deal tbh
There‘s a bunch of reasons. Not leaking sessions is one, having people frequently think about and use their password is another. It‘s generally good practice to kill sessions after they‘ve been active for a while.