How about implementing a session expiration cookie... ? Like... after 15 minutes of inactivity, session is automaticaly closed.
The session will be closed after some minutes when you close the browser. The session shall not be closed afetr some time and ispconfig has some code that makes sure that the sesion can not expire as many administrators have their admin console open all day.
time If they were to implement this idea it should be able to be set to an amount of time that suites the user. Say from 1 min to 24 hours.