Replay attacks with cookie session

Planting the seed here led to quick ripening and plenty of pesticide.

<snip>

Thanks for the fish, all.

So, does that mean this will likely be taken out? If so, I would vote that it at least be provided as an option if not the default. It's certainly useful for developers who understand the security concerns and still feel that it would be an appropriate method of session storage for their application.