Yeah, I tried putting this line of code [ini_set("session.gc_maxlifetime", "36000"); if you're curious] in every page that's supposed to set the session's lifespan, but it turns out there's this php.ini file that controls this sort of thing, and as far as I can tell, it's server-wide.
Which basically means, the web host hates us. Sorry, I don't know if there's anything I can do.
We're closing on a house at the end of the month, and then I can start seriously looking at servers and business class internet access from home.. but it won't happen any time soon.
In the mean time, we're ultimately under bluehost's control. |