To be honest, the default behavior of silently resetting the session and not throwing seems wrong to me. It's reasonable to only store user auth information in a cookie, so resetting the session doesn't have the intended effect of logging out the user.