// login action
Person person=securityHandler.login(getFilterConfig().getServletContext(), httpRequest, httpResponse, userName, password);
if(person != null) {
// login successful, return originally requested resource
// don't like showing login in url because can't bookmark so redirect to it
httpResponse.sendRedirect(httpRequest.getContextPath() + accessingURL);
} else {
// error on login, populate error and go to login page again
// make sure to set hidden accessingURL again
// set response header to alert ajax calls of a login error.