Is it actually the case that filtered replication can be used cleanly for access control now? My understanding from the various docs was that currently you can write a filter but not require that users replicate through it -- that is, if you have permission to replicate, you have permission to replicate and that's it. For real access control using this I think you'd need something like a permission to replicate distinct from permission to read and a permission to replicate only through a specified filter. I suppose I'm off to have a look through Max's source, but if I'm wrong about these things I'd appreciate the correction...
...ok, back. Right now there appears to be no access control at all. Granting that this is a relatively early-stage project so it doesn't necessarily matter too much, but my question still stands.