The tradeoffs with session length are actually quite interesting. Obviously infinite sessions are the best in terms of the initial friction, and thus be great for creating user engagement and minimizing the number of users who drop off the service due to having to log in again. And even if the users stick, if they need to log in too often they'll hate it (as seen all over these comments).
But on the flipside, the infinite session might not be a benefit in the long term. A user who signs in just once when creating account will have no idea of how to log in. They'll have forgotten their password because they only used it the once, they've lost access to their recovery email account due to changing jobs, etc. And while any single one of these issues would have been trivial to fix if noticed quickly, letting them pile up for a year means you might have very few ways of proving it really is you when that nominally infinite session finally gets killed for some reason.
I very nearly had this happen last month. I had been intending to close an old phone number from a different country, where I haven't lived in 15 years. But I also happened to try to log into a PSN account for the first time in years (consoles basically never require new logins); the password mysteriously did not match the one that was stored in my password manager, and it was only that old phone number with weeks left to live that got me back in.