Here's what I did:
Here's the diff
After going through this effort, I wondered why COREBlog does not have this OOTB (there's the word again ;))
Maybe it's me. In a perfect world, we probably do not need authentication to post comments. But in my world, users will abuse the system if there's no authentication.
The patch for both Members only Post and Comment is lightly tested. No guarantee that it'll work with the next version of COREBlog.
YMMV
Trackback is http://myzope.kedai.com.my/blogs/kedai/6/tbping
