I don't think requiring that your user(s) be compromised before this becoming an issue is a valid defence. Especially when cookies are easily stolen using something like Firesheep or as simple as forgetting to logout of a public terminal. You should ultimately be putting in systems that, if in the event of a compromise, you can mitigate the cost to the user.
My hope is that expiration will be soon baked-in (or easier to bake in), after reading https://github.com/rails/rails/pull/11168