Thanks Rob. To give u just an example lets take this usecase:
Someone created a WikiPage. He adds few off his friends as users to the wiki page. Now some friend of his wants to play a prank and tries to delete the wikipage. To stop this, we as part of the deletion, checks for lot of things includig credentials/password of the user requesting for a deletion. Thing to note here is that,this cred is different from the HTTP Basic Authentication(ChallengeResponse)parameters. We pass this authentication credential to make sure no tom,dick and harry is bombarding our server with spammed requests.We only recognize and honor web service request from our recognized partners. The actual user credentials who is requesting a deletion goes as part of entity to the deletion webservice call. I hope this makes sense. Regards Surjendu

