Is the name and passwd passed through the Session object? If this is the case, it looks like we could perhaps extract the name and passwd parameter from the Session Object parameter before it is saved (encrypted) to the database.
What do you think?
Hansi



