Since you will not indicate which authentication you use, I’m going to make some big assumptions about the fact that you have some kind of login / action page that you specify a username and password using those parameter names. If you have other fields - for example, hidden fields, to prevent fakes with cross-site requests, you also need to enable them. I also assume that you know that you have not authenticated yet. There are ways to detect this, but I'm not going to cover them. I also assume that you submit actions to the website, not some API that requires a separate type of authentication.
, , POST ( ) . , . - cookie .
. , AJAX ( HTTP_X_REQUESTED_WITH - ), JSON , HTML, .
cookie , AJAX - .