Agreed. Worse still, the username can end with a "|". This shows that tainting mode is useful.
In reply to Re: Re: setting a cookie on login by ambrus in thread setting a cookie on login by reklaw