, ( , ) . - , - .
, . , HTTP Digest - , WWW-Authenticate Authorization. , , , REST.
, , HTTP Basic/Digest , -, , cookie. , , , (, " ", 401) . Basic/Digest/Certificate, Ajax , , CSRF.
, cookie , , .
:
. , . , Cookie REST , , , .
EDIT ( ):
, , cookie . , . , , CSRF Basic/Digest/Cert ( 2003 , ), cookie. . , cookie, cookie HTTPS.