Currently, only top-level dirs are password-protected. Instead, there should be a list of dirs to be protected, in an administrator-managed file.