* the magic works by wrapping uid in a marker class, so if some code unwraps this in the calling tree, security checks will be reenabled