in reply to Re: setting a cookie on login
in thread setting a cookie on login

Agreed. Worse still, the username can end with a "|". This shows that tainting mode is useful.