This denies access to all users that are not logged in. Because of the default rule that grants access to
the resource if the current user is not matched by an earlier rule, all logged-in users can successfully
access files in the Reviews folder.
You can specify multiple roles or usernames in the roles and user attributes by separating them with a
comma.
It’s important to understand how the RoleGroups element of the LoginView works. Although you can
specify multiple RoleGroup elements that may all apply to a certain user, only the first that matches is
displayed. Consider a user called Alex assigned to the role WebMasters and to the role Managers and a
web page with the following LoginView: