For now all authenticated users have their session stored in long life cookies.
We should allow users to opt-out of this using a "remember me" checkbox.
- checked by default
- no "remember me" for super admin sessions
- no "remember me" for super admin authenticated as another user