> Does even anybody remember the good old HTTP basic acess authentification? This is one of the most accessible ways of protecting ressources, it can be consumed by any HTTP client (!), and it is just reduced to the basic.
Basic authentication is fine if all you need is to control access to documents, but it can not be used for access delegation or any scope control.