Any endpoint could automatically update the user session token when it detects it's about to run out and update the cookie that it is stored in.