Ok, also please note that I accidentially used get instead of post for the form variables and have reuploaded it with the proper changes. I plan to put stuff in the language files once I get a fully tested and verified working version for both 1.3.7 & 1.3.8 as well as for the register globals on and off.
I have fixed the sub directory issue by using HTTP_SERVER and HTTPS_SERVER as well as DIR_WS_CATALOG & DIR_WS_HTTPS_CATALOG.
I did test passing the session security token through on 1.3.8 but I think the problem is that the session data is different from the admin side to the front side so the securityToken is not valid from the admin to the Catalog side. I believe that after the error a front end securityToken is generated and is used that is why once you click login a second time you are able to login, but that is just what I think is happening, not 100% at this point but will be doing more research.
I am open to any suggestions on ways to improve my code, I'm new at this and haven't coded PHP is a few years so I know it's probably pretty ugly. I plan to streamline it as much as I can, but needed the mod so i got it working, on 1.3.7 anyway and now I want to streamline and get working properly on 1.3.8.
Thank You,
Sid Smith