On 4/29/13 1:07 PM, "Brewer, Edward L" <lee.brewer at Vanderbilt.Edu> wrote: >Would this change to the login-mobile.jsp be a safe fix? Why even check the parameter? Just hardcode the action. It's your script, so obviously it's not going to be used with container managed security unless you later decide to do that. -- Scott