Using "Form" based, then u need to use a particular type of form j_security_check where u have to do a kind of login form. That gets value from particular from browser and keep it.
U can chek this link out
This is done in GF bt rest the procedure is same. I have worked in jboss as well. So can check it out. If any issue let me know.
Anyway thank you for your help.