Definitely. Additionally, a little sign in the gui somewhere to the
effect of "you are authenticated as user *blah* on this page" - so that
people can tell when that info is being sent and when it isn't. I
consider it nothing more than luck that most browsers are currently
intelligent enough to not send authentification information for one site
to another by default.
Brian