We have constructed a decarator based solution to secure a service on server side, so essentially the securing of a REST service is totally independent of the development of a service. However we will need a more formal documentation about the architecture and the usage (server side, client side).