Here is the scenario:
Using OAuth 2.0 we log in with Identity Server 4 and create a session cookie with an expiry of 6 months. We return an access token with a 1 hou