diff --git a/pom.xml b/pom.xml
index 6a83c0e..25ace09 100755
--- a/pom.xml
+++ b/pom.xml
@@ -455,6 +455,7 @@
                                         <pathelement location="${commons-lang:commons-lang:jar}"/>
                                         <pathelement location="${commons-collections:commons-collections:jar}"/>
                                         <pathelement location="${commons-logging:commons-logging:jar}"/>
+                                        <pathelement location="${commons-io:commons-io:jar}"/>
                                         <pathelement location="${net.sf.ehcache:ehcache-core:jar}"/>
                                         <pathelement location="${org.slf4j:slf4j-api:jar}"/>
                                         <pathelement location="${org.slf4j:slf4j-log4j12:jar}"/>
diff --git a/src/main/java/us/jts/commander/panel/UserDetailPanel.java b/src/main/java/us/jts/commander/panel/UserDetailPanel.java
index 8ab4f2e..531640d 100644
--- a/src/main/java/us/jts/commander/panel/UserDetailPanel.java
+++ b/src/main/java/us/jts/commander/panel/UserDetailPanel.java
@@ -636,6 +636,7 @@
                 protected void onSubmit( AjaxRequestTarget target, Form form )
                 {
                     log.debug( ".onSubmit assign" );
+/*
                     HttpServletRequest servletReq = ( HttpServletRequest ) getRequest().getContainerRequest();
                     if ( servletReq.isUserInRole( "rbac_admin" ) )
                     {
@@ -645,6 +646,7 @@
                     {
                         log.debug( "User NOT RBAC_ADMIN" );
                     }
+*/
 
                     User user = ( User ) form.getModel().getObject();
                     if ( assignRole( user, roleSelection ) )
diff --git a/src/main/resources/CommanderDemoUsers.xml b/src/main/resources/CommanderDemoUsers.xml
index 2934c07..ad6207b 100644
--- a/src/main/resources/CommanderDemoUsers.xml
+++ b/src/main/resources/CommanderDemoUsers.xml
@@ -11,7 +11,7 @@
         <FortressAdmin>
 
             <adduser>
-                <user userId="test" password="test" description="Commander Demo User" ou="demousrs1" cn="test" sn="user"  pwPolicy="Test1" beginTime="0000" endTime="0000" beginDate="20090101" endDate="20990101" beginLockDate="none" endLockDate="none" dayMask="1234567" timeout="0"/>
+                <user userId="test" password="test" description="Commander Demo User" ou="demousrs1" cn="test" sn="user"  pwPolicy="Test1" beginTime="0000" endTime="0000" beginDate="20090101" endDate="20990101" beginLockDate="none" endLockDate="none" dayMask="1234567" timeout="0" photo="TestPhoto1.jpeg"/>
             </adduser>
 
             <adduseradminrole>
diff --git a/src/main/resources/TestPhoto1.jpeg b/src/main/resources/TestPhoto1.jpeg
new file mode 100644
index 0000000..e178cf2
--- /dev/null
+++ b/src/main/resources/TestPhoto1.jpeg
Binary files differ
