The funny thing is that CAN-SPAM mandates 1-click opt-out, and requiring login to unsubscribe is specifically prohibited.[1] So most websites already have code to include and verify auth tokens in emailed links, which they utilize when they are mandated to.
But somehow they haven't figured out that it is in their own interest to do so the rest of the time.
[1] http://blogs.boomerang.com/blog/2009/06/16/can-spam-2008-uns...