Hi Dane,
you are right, this has been solved before :) For example you can
transfer your sessionId in your RPC payload and then correctly pair
request with session on the server side. This approach was implemented
in acris framework and described in the security chapter here:
http://code.google.com/p/acris/wiki/Security
Only problem is with the App Engine, because acris-security is not
currently deployable on App engine but anyway, you can inspire by the
solution or extend it to be deployable on app engine. Help is very
appreciated.
Peter