fix: use max-age for all cookie expirations
in addition, remove cookie expiration for AURREMEMBER -- we don't really care about a session time for this cookie, it merely acts as a flag given out on login to remember what the user selected
Signed-off-by: Kevin Morris kevr@0cost.org