in reply to Re: setting a cookie on loginin thread setting a cookie on login
Agreed. Worse still, the username can end with a "|". This shows that tainting mode is useful.