> I had to comment out this part > > p:resultIfMissing="true" Because that's an API/code change. > Is there a way to deny login if the password expiry timestamp is in the past ? If you figure out how to rewrite the thing without core code changes. -- Scott