4
No ... this doesn´t suck.
Any other handling would be inapropriate.
a) you should not be able to login with the users password except he gave it to you because otherwise every webadmin could fake useractions/posts/... easily
(ok technically you can still go into the database and do stuff but it would be harder)
b) users tend to use the same password for several accounts and sites. If you get hacked the password would be disclosing even more than just the hacked site.
c) several other reasons like these two ...
But looking at the smilie in your last post i'm sure you already realized this.