We should explain how to secure the whole application, while excluding the authentication-related URLs if using a repoze.who !RedirectingFormPlugin-like challenger.
See also: http://groups.google.com/group/turbogears-trunk/t/97c0e11a4d538a1d
https://github.com/TurboGears/tg2docs/issues/10
https://github.com/TurboGears/tg2docs/issues/10