That code is filled with all sorts of horrors (Sql injection, passwords in plain-text in DBs, passwords sent in query-string, all logic in web-layer), but redirecting in a using block is ok, the disposers will always be called (outside of fatal exceptions like StackOverflows)