- user mysql_escape_string on all fields before saving (oops!) :) - add a committee login function to set SESSION variables.