Your tokens should defiently have expiry times on the range that you would need to login again.
I would prefer a 999 year login cookie.
A well designed browser stores the cookies with similar security to the built in password manager anyway
I would prefer a 999 year login cookie.
A well designed browser stores the cookies with similar security to the built in password manager anyway