Authentication and need for at least a pseudo "session state" always seems like the trickiest part of building a 100% RESTful app. Anyone have details/examples on ways to address these?
Login:
PUT https://example.com/credentials
{"username":"foo", "password":"bar"}
Check if user is logged in: HEAD http://example.com/credentials
Cookie: ...
Get current user: GET http://example.com/credentials
Cookie: ...
Logout: DELETE http://example.com/credentials
Cookie: ...
From the point of view of the one client, it's no less "real" than any other resource.