>>>>> If you use the httpauth and the cgiauthurl method, you can restrict a path
>>>>> like /private/* to be accessible only under the authenticated request uri.
->>>>>> Note that if editing is enabled, then you should set the restriction in locked_pages too
+>>>>>> Note that if editing is enabled, then you should set the restriction in
+>>>>>> [[plugins/lockedit]]'s locked_pages too
>>>>>> or they may be able to view pages by editing the page= value in the editor's
>>>>>> query string. --[mjr](http://mjr.towers.org.uk/)