Basic authentication (at least) would be a `nice-to-have` feature if the REST services could be exposed.