"Restoring" a session means simply making a new request within the timeout
period. Whether the browser tab has been reloaded in the meantime is

I still doubt this is anyhow more secure than session resumption in XEP-0198 (which btw requires real re-authentication).

