When users are removed from an ncsa_auth style password file, squid does not
seem to reauthenticate them.
Even on a subsequent browser restart, they are re-authenticated but
worse...it allows them into the proxy even though they are not now in the
password file.
Testing with a user not in the password file denies them properly.