Other idea :
would it be possible (now or in a future firmware) to have wds and normal wifi supplicant using two differents authentication & encryption scheme ?
wds bridge could use shared key while others 'normal' clients would use ... what they want...

I can't figure now if this is totally absurd or not. If someone has good wifi knowledge, help is more than welcome.

JF