It's a pretty widespread practice. I think it's the Rails default.
It's not that hard to just set up a Redis or whatever store to handle stuff like this, I never understood why people whouldn't bother.
All session stores use a cookie to store a unique ID for each session...For most stores, this ID is used to look up the session data on the server, e.g. in a database table.
(obviously you'd substitute Redis for the database table mentioned above)