Whenever i close the page in which i have opened theserversid.com with out logging out, the next time when i enter the url in the address bar it is automatically logging into my account. I think it would be better if the session is invalidated as soon as i close the page.
I disagree. I think majority of the web pages (e.g. OTN - Oracle Technology Network) did the same thing, that is, didn't invalidate the session and use the cookie to identify the person who access the page. This saves me effort to login each and every single time.
When you login there is a check box that allows you to save the cookie or not. This was put in to save you from logging in all the time (which was a pain for me, that is for sure!).