I would suggest going the cookie/session route. Most browsers will store the username/password for basic HTTP authentication, so even if you manage to remove them from the server end, the browser will just send them back automatically when asked for them.