Right but I also think setting this to a value like 0
should possibly (if it doesn’t cause too many support issues, or is too technically difficult) do the “cookie only works for duration of browser session” behavior. So the description of the site setting could indicate that.
maximum session age [default 1440 hours]
User will remain logged in for n hours since last visit. When set to 0, user will be logged out when the browser is closed.