Hello,
Firstly, I should have added Zenphoto gallery was set up as private gallery so Zenphoto--Option--Gallery--Gallery type was set to private.
Your hint has been useful indeed. Actually, the moment I read your third sentence it was all clear in my mind. I have read the Rules of protection and visibility for Zenphoto objects a number of times but somehow every time I took for granted that passwords would result in the user having to type an additional password to access the album.
In order to clear this/my confusion and help out other Zenphoto users, I've partly rewritten the section (draft-like). If you'd like some support from a Zenphoto user standpoint, this is the way I would put it:
----------
...
Galleries can be either public or private.
In a public gallery there are four possible states of an object as described below. Logged on Zenphoto users may have rights that override local password protection and published state. See above.
1.- Published/not password protected: Any one can see these items
2.- Not published/not password protected: People have to "know about" these items to view them. (That is they need to know the URL, they will not show in menus if the visitor does not have the appropriate credentials.)
3.- Published/password protected: People will know of these items (they will show in menus) but not be able to access them without the password.
4.- Not published/password protected: These are truely restricted to "logged in users". They require the appropriate credentials to access or see in menus.
Private galleries are equivalent to having all objects password protected. In a private gallery objects can be granted any of the four possible states listed above.
The use of the groups plugin alongside setting a gallery private can allow the admin to set different permissions for different albums based on group membership. For a private gallery hosting different groups and album permissions to be properly configured, all albums must be set as unpublished. Thus, only users/groups with permission to access a given album would be allowed to view/edit it. If, in this context, the status of an album were set to published, any user/group would be able to access it. For global privacy and local access permissions to apply, objects should only be allowed the following state:
Album unpublished/ password-protected gallery: These are truely restricted to "logged in users". They require the appropriate credentials to access or see in menus.
----------
Greetings,