It doesn't really make sense because ALL other settings are saved correctly in the database except those two. Unfortunately I don't know enough PHP to investigate the code behind the Save button there...
Yeah I've also set Agent Session Timeout to 0, doesn't make any difference. As soon as the "Invalid CSRF Token CSRFToken" messages start to creep up in the logs, I get logged out and then I need to clear the ost_session table to be able to log in again (all browsers behave the same in this regard, tried Chrome, Edge, Firefox).