Block a user
Make the login page url configurable
Make the logged-in-ness detection better (detect after post on user/login page)
Make the login form configurable or autodetect