/* Modified by NaX from release 4.6 to use HTML forms, HTTP-AUTH will not run under PHP installed as CGI [http://drupal.org/node/28408]
   Modified by Gestaltware for additional enhancements

Settings
-------------
  + consolidated http-auth and html form setting to one variable
  + removed CSS, request error message variable settings
  + changed HTML Login and Password Reset form variable settings to represent message only (form logic embedded in functions, not settings)
  + added configurable HTTP-AUTH realm (Junyor - April 29, 2005 - 04:25)

HTML/Reset Forms
-------------
  + Reset Password form is not shown unless there is a Password Reset message variable
  + added inline error message
  + added simple dialog page template system

This likely breaks Drupal programming convention, but I think is still a step further than embedding CSS/page logic as a setting. Basically, there is a new file <em>dialog.tpl.php</em> which you put in one or more of your theme driectories, and skin as you wish to match your site. If this file is not found for the theme, then there is a very simple default dialog that will be used. This dialog (whether themed or the default) gets called by the function <em>dialog_page</em>, whose purpose is to display a small amount of text that bypasses the function <em>theme_page</em>. Examples might include trapping all error messages, loss of DB connectivity, or in this case, a login/password reset form. I would recommend moving <em>dialog_page</em> into <em>theme.inc</em>, but since I'm not yet running 4.7x, haven't seen how much has changed.

Authentication/Logging
-------------
  + removed duplicate failed log message for HTML form
  + added failed log message for http-auth
  + invalid login attempt logged only if username and password is provided
  + superuser (uid 1) automatically authenticates regardless of access settings

Misc
-------------
  + fixed password reset logic ($account was passing even with no matching record, likely same problem in user.module)
  + remove redundant code (empty functions: _securesite_user_pass, _securesite_settings, _securitesite_auth; duplicate functions: securesite_t; renamed functions: securesite_user_pass to securesite_user_auth)

  
  Modified by NaX
  
Form CSS
-------------
 + left align form buttons so IE does not break the layout of the dialog.
 + 0 margin and padding on form to remove the extra white space created in IE around the form.
  
Authentication/Logging
-------------
 + moved module_invoke_all('exit') for logging of Anonymous users (on logout a user gets logged twice once as the user on the login page then after redirect as a Anonymous user on home page). Anonymous should be logged so to track possible hacking attempts and for logging of search engines by other modules.
 + set page title to login so page hit would be recognized as for the login dialog.
 
Misc
-------------
 + force redirect back to home after logout (to prevent caching of the home page, and to clear the url)
 + moved page exit's to more logical places (only when redirect and dialog output)
 + rename dialog.tpl.php to securesite-dialog.tpl.php, so not to be confused with any other modules.

*/
