Security Architecture
---------------------

Users
-----

Objects representing users may be created in Principia
User Folder objects. User objects maintain the information
used to authenticate users, and allow roles to be associated
with a user.



Permissions
-----------

A "permission" is the smallest unit of access to an object,
roughly equivalent to the atomic permissions seen in NT:
R (Read), W(Write), X(Execute), etc. In Principia, a permission
usually describes a fine-grained logical operation on an object,
such as "View Management Screens", "Add Properties", etc.

Different types of objects will define different permissions
as appropriate for the object.



Types of access
---------------

A "type of access" is a named grouping of 0 or more of the
permissions defined by an object. All objects have one predefined
type of access called Full Access (all permissions defined by that 
object). A user who has the special role "Manager" always has Full 
Access to all objects at or below the level in the object hierarchy 
at which the user is defined.

New types of access may be defined as combinations of the
various permissions defined by a given object. These new
types of access may be defined by the programmer, or by
users at runtime. 




Roles
-----

A role is a name that ties users (authentication of identity)
to permissions (authorization for that identity) in the system.
Roles may be defined in any Folder (or Folderish) object in the
system. Sub folders can make use of roles defined higher in the
hierarchy. These roles can be assigned to users. All users, 
including non-authenticated users have the built-in role of 
"Anonymous". 

Principia objects allow the association of defined roles 
with a single "type of access" each, in the context of that 
object. A single role is associated with one and oh of identity)
to permissions (authorization for that identity) in the system.
Roles may be defined in any Folder (or Folderish) object in the
system. Sub folders can make use of roles defined higher in the
hierarchy. These roles can be assigned to users. All users, 
including non-authenticated users have the built-in role of 
"Anonymous". 

Principia objects allow the association of defined roles 
with a single "type of access" each, in the context of that 
object. A single role is associated with one and oh of identity)
to permissions (authorization for that identity) in the system.
Roles may be defined in any Folder (or Folderish) object in the
system. Sub folders can make use of roles defined higher in the
hierarchy. These roles can be assigned to users. All users, 
including non-authenticated users have the built-in role of 
"Anonymous". 

Principia objects allow the association of defined roles 
with a single "type of access" each, in the context of that 
object. A single role is associated with one and oh of identity)
to permissions (authorization for that identity) in the system.
Roles may be defined in any Folder (or Folderish) object in the
system. Sub folders can make use of roles defined higher in the
hierarchy. These roles can be assigned to users. All users, 
including non-authenticated users have the built-in role of 
"Anonymous". 

Principia objects allow the association of defined roles 
with a single "type of access" each, in the context of that 
object. A single role is associated with one and oh of identity)
to permissions (authorization for that identity) in the system.
Roles may be defined in any Folder (or Folderish) object in the
system. Sub folders can make use of roles defined higher in the
hierarchy. These roles can be assigned to users. All users, 
including non-authenticated users have the built-in role of 
"Anonymous". 

Principia objects allow the association of defined roles 
with a single "type of access" each, in the context of that 
object. A single role is associated with one and oh of identity)
to permissions (authorization for that identity) in the system.
Roles may be defined in any Folder (or Folderish) object in the
system. Sub folders can make use of roles defined higher in the
hierarchy. These roles can be assigned to users. All users, 
including non-authenticated users have the built-in role of 
"Anonymous". 

Principia objects allow the association of defined roles 
with a single "type of access" each, in the context of that 
object. A single role is associated with one and oh of identity)
to permissions (authorization for that identity) in the system.
Roles may be defined in any Folder (or Folderish) object in the
system. Sub folders can make use of roles defined higher in the
hierarchy. These roles can be assigned to users. All users, 
including non-authenticated users have the built-in role of 
"Anonymous". 

Principia objects allow the association of defined roles 
with a single "type of access" each, in the context of that 
object. A single role is associated with one and oh of identity)
to permissions (authorization for that identity) in the system.
Roles may be defined in any Folder (or Folderish) object in the
system. Sub folders can make use of roles defined higher in the
hierarchy. These roles can be assigned to users. All users, 
including non-authenticated users have the built-in role of 
"Anonymous". 

Principia objects allow the association of defined roles 
with a single "type of access" each, in the context of that 
object. A single role is associated with one and oh of identity)
to permissions (authorization for that identity) in the system.
Roles may be defined in any Folder (or Folderish) object in the
system. Sub folders can make use of roles defined higher in the
hierarchy. These roles can be assigned to users. All users, 
including non-authenticated users have the built-in role of 
"Anonymous". 

Principia objects allow the association of defined roles 
with a single "type of access" each, in the context of that 
object. A single role is associated with one and oh of identity)
to permissions (authorization for that identity) in the system.
Roles may be defined in any Folder (or Folderish) object in the
system. Sub folders can make use of roles defined higher in the
hierarchy. These roles can be assigned to users. All user