Hi, I've just verified that XDM still exhibits this bug, contrary to what Steve Durham said about PAM fixing it. I added /bin/true to /etc/shells, and changed a user's shell to /bin/true. XDM still logged me in.
T -- The two rules of success: 1. Don't tell everything you know. -- YHL