All rules in INI files
Whitelist public actions in auth_allow.ini, define role permissions in auth_acl.ini. Stop sprinkling allow/deny calls across controllers.
Define authentication and authorization rules in INI files instead of scattering allow/deny calls across every controller. A thin wrapper over the official Authentication and Authorization plugins.