-
SchmagaHimself Whatever auth info is currently sent as part of a cookie could (and should) have been standardized as an auth mechanism instead. This would of course require browser vendor support, which is why it will never happen except in an alternate reality