In point 4, a separate 'remember me' cookie should persist indefinitely (not just through the session) which has the users hashed login info, details are provided in the link above on how this is accomplished. This is how Facebook, Google, linked in yahoo, most other web apps handle login. If anyone uses linked in, they will likely notice they rarely have to enter their credentials, but to be honest it is more of a convenience for users as it is simply allowing them to by-pass the login if they have enabled 'Remember me'.
This link has a good summary of the method and some ideas to make it even tighter. http://jaspan.com/improved_persistent_login_cookie_best_practice
In terms of the Aware links, IMHO they should NEVER contain Login parameters (even if obscured), there are too many ways this info can be easily hijacked. What I am suggesting is to have any link coming into the app interrogated for credentials (but those credentials should not be parameters). So the incoming link would be checked first as Guest, if no, then via cookie method above, failing that - manual prompt. Only once a valid session is established the URL parameters are processed.
Perhaps that happens already? However, my understanding is that if the link UID/PW is not valid the user is pushed to the login screen (which is good), but if they then login the link parameters are not processed? Is my understanding incorrect? (I meant to test this today, just ran out of time).
Does that help?