you restricted folder to anonymous, but you force people to have a username through the template...
from your description it doesn't seem a bug in HFS, but an incongruity in the way you use it. am i right?
if it is so, TOG should warn people that the login-version is not compatible with @anonymous.