Even if you could shrink that state down to something reasonably small, it still introduces the problem of the client and server getting the state out of sync.
But it becomes much worse with mobile devices, such as a phone. I don't want to lose the state of my browser tabs every time I get into an elevator.
I guess it very much depends on your usage - I wonder the proportion of users who add to a shopping cart and go back to it without creating an account.
Of course, we're also ignoring session local storage, in memory storage etc... for alternate solutions.
Local storage is another story and probably a good alternative to storing something server-side, at the cost of more back-and-forths to validate data isn't outdated.
> I'm not certain whether it's unreasonable or it's become an expected norm; you don't expect to be able to leaving a shopping cart full if you're leaving a physical shop, for example.
It has become the norm, which is why it's (IMO) unreasonable to change that. Realistically, for a solution to be doable it needs to allow for saving the cart state, as otherwise websites will simply resist the change.
Let me gently refer you to the classic paper from 1994, "A Note on Distributed Computing".
Stealing tokens via XSS is way harder to solve.