Chris McDonough <> added the comment:

For the record, in repoze.who 1.1, the userid string gets base64 encoded in the 
cookie so this 
should not be a problem.  Old cookies continue to work via a b/c shim.  I'm 
going to close this 
issue as a result.

