* json will do basic authentication -- not sophisticated, but works * regular request will redirect to login page * csrf token * /movies/<option> instead of <lang>