This default is only going to create security risks as users login on public-facing devices, like a library or device they don't own.
I hope you don't make PII or transactions available inside your app, otherwise I would urge escalating this issue internally.