Hi Luke,
When you post about the book, can you please specify the version (MX vs MX 2004) and a page number? Makes it easier to find out what you're talking about.
Anyway, you're right in your assumptions. When a user has an empty access level, they gain access to the protected areas. Therefore, it's important a user always has an access level specified. Take a look at the book's extension article about adding users, located here:
http://Imar.Spaanjaars.Com/QuickDocID.aspx?QUICKDOC=209
Somewhere half way down the article you'll find a section called "Adding the Insert Record Behavior". Look at its subsection "A Little Explanation" for an explanation about the security hole, and three ways to close that hole.
Hope this help; otherwise let me know.
Imar
---------------------------------------
Imar Spaanjaars
Everyone is unique, except for me.