I've set up pass-through authentication and it's been working fine, however I recently discovered that anyone could log in as anyone if they log out then log back in as another user with the password field empty. Did I miss something when I set this up?