From RFC:
If an attribute appears more than once in a cookie, the behavior is undefined.
It is not possible to set a cookie like this; at least there is no cross-browser way to do this. (Also, as far as I know, the corresponding attribute is “Max-Age” and not “expiring”, perhaps this name is part of the YUI api.)
Ending a session after a certain period of time is usually what the secure server code does by itself and explicitly. (In other words, a session cookie is explicitly rejected as invalid if its timestamp indicates excessive age.)
source share