You should not rely on the browser to delete old cookies. The browser will delete cookies by comparing the expiration date with the client, not the server. Therefore, if you install the expiration servers within 30 minutes, but the client has a one-year clock behind, then the client browser will not delete the cookie for another year and 30 minutes.
Before authorizing a request, always check the expiration servers.
source
share