Some predefined security features using permissions
All requests to an OpenACS package's /www subdirectory
All requests to an OpenACS package's /www subdirectory are refused unless the visitor has the read privilege on the site node object mapped to the package instance.
All requests to an OpenACS package's /www/admin subdirectory require the admin privilege on the site node object mapped to the package instance.