in src/main/java/org/apache/sling/auth/form/impl/FormAuthenticationHandler.java [695:709]
private boolean needsRefresh(final String authData, final long sessionTimeout) {
boolean updateCookie = false;
if (authData == null) {
updateCookie = true;
} else {
String[] parts = TokenStore.split(authData);
if (parts.length == 3) {
long cookieTime = Long.parseLong(parts[1].substring(1));
if (System.currentTimeMillis() + (sessionTimeout / 2) > cookieTime) {
updateCookie = true;
}
}
}
return updateCookie;
}