AuthHandler.get_user()
can handle the basics now: authentication, perm checks etc.
not really tested yet though, other than unit tests