Earlier quoted context omitted.
You can do anything until I close a page. Stealing cookie might allow you to continue after that.
I will have done anything I want to within one second of you logging in. There is no need for later attacks
It's the same reason OAuth uses expiring tokens. If you think that doesn't help and you're surely smarter than the whole security community who has been developing these standards for decades, please write a specification yourself and let us review it to see how great that is.