Oops, I forgot to address the question of authorization based on identity and resource instance state. I'm assuming I'd do that inside the ServerResource itself, right?
-- View this message in context: http://restlet-discuss.1400322.n2.nabble.com/combining-role-and-method-authorization-tp7366193p7368614.html Sent from the Restlet Discuss mailing list archive at Nabble.com. ------------------------------------------------------ http://restlet.tigris.org/ds/viewMessage.do?dsForumId=4447&dsMessageId=2934972

