Implementing such a thing securely is not a job lightly undertaken. It isn't one that I have the time for, but patches are welcome.
In any case, what's preventing you from using digest auth for your ajax calls? That's what the current calibre content server frontend does.
|