in reply to setting a cookie on login
Agreed. Worse still, the username can end with a "|". This shows that tainting mode is useful.