Add accessors for ACL for plain Principals

This allows consuming code to be orthogonal between permit/deny and
user/group.  Previously, that code would have to have code for each
combination of those cases.
2 files changed