If you set the cookie expiration time long (like 30 days or 60 days) then removed the "remember me" checkbox from the login.tmpl and logout.tmpl pages, the user would login, and the login would last only for the browser session (yet not a session - still using cookies) it's just that if they return later, the remember cookie isn't set, and they will have to re-login.
that might work for you.