This ticket is focused on the applications being able to use the REST based interface to set/get information for annotations, users, journals, issues etc. (essentially PLoS ONE specific OTM objects). This should also include:
- Security wrappers so PLoS can control who can perform these operations
- Maybe provide a way for PLoS to configure which 'annotation types' are allowed
- Allow PLoS Admins to set any annotation content body (specially Comment annotation not being escaped)
- Expose enough of the security policy information to easily allow PLoS to be able to modify it (Maybe just the list of users?)