Strictly authenticate username / password, which is as secure as sending a login form to the same place. The security issue arose from what you are doing (or not doing) as a function of success and future ajax requests, since javascript can be faked / modified on the fly to interfere with the variables (especially for the user) that you set.
source share