the password is hashed with sha1 so that the database does not need to store the actual password
This recommended approach is not good security practice for password storage. If the database is compromised, your passwords are vulnerable to rainbow table attacks. See http://en.wikipedia.org/wiki/Rainbow_table