That's a tricky one, though - you're basically deciding for your users if their credentials will be at risk. As one of your users I'd rather make that call for myself...

You're always making that call, either client or server side.

