loginUserId parameter in _GET or _POST for direct login without username and password. This can be secured by: - must login after x days from set loginUserId on - can only login with loginUserId in given time range - flag lock loginUserId
- db create shell script for ACL\Login to reset full database to known good stated - basic tests written to check core login class