I deleted an account of a user that was currently logged into our forums. While the account deleted successfully, the user was able to continue to post to the forums and access the web site. The username showed up as "Deleted" for each post of course.
I consider this to be a bug, albeit a minor one as it will not happen often. However, the server's list of accounts is the list that access should be compared against, not a cookie on the client's machine that is marked as already validated.
In cases like this (we had one in the recent past) a Ban IP would be nice.
Ban by IP is an option.
-- Six Demon Bag Jack Burton: Hey, what more can a guy ask for? Egg Shen: Oh, a six-demon bag! Jack Burton: Terrific, a six-demon bag. Sensational. What's in it, Egg? Egg Shen: Wind, fire, all that kind of thing!