By default the JSESSIONID cookie is expired when you close the browser, but how long is the associated HttpSession really valid on the server side?
JSESSIONID
HttpSession