Is there a good example out there of setting up security based on some sort of ownership system?

I'm working my way though the Zope book. What I would like to be able to do is allow the User who created a message to edit only "their" messages (the messages they created). I think I've read all the relevant chapters of the Zope book and I can't find a place where it explains that. Did I miss is somewhere?

Could some one point me in the right direction for figuring this out?

If this isn't in the Zope book it may make a good addition. There are lots of instances I can think of in application where someone would want to grant privileges based on ownership.



