A useful hack I've implemented in several projects is to accept the stored password hash as a valid password.
It is generally possible to impersonate a user but there are always subtle differences in the way those sessions work.
Accepting the hash lets people with database access perform a real login if needed.