Hi Andy,
I think something like the existdb approach would be more what I would expect. The ability to config a default http user with reduced permissions, and then a way to change the user associated with the session e.g. session:set-current-user http://exist-db.org/exist/apps/fundocs/view.html?uri=http://exist-db.org/xqu...
Currently, database users and sessions are treated separatedly, but I would really like to bring them closer together. Thanks for the link.
Christian