I just made edits to the bump code so that it snags the userid from session info rather than from a URL parameter. If we decide to add logging and display for thread bumps, we'll make sure not to use something as insecure as that.

- h