[EP-tech] privileges of editor role

by default the "editor" role has full access on staffonly documents,
even if you can limit its editorial rights.
is this behaviour correct?
an editor can always see a staffonly document in the live archive
even if is not approved by him.

someone has a better way to reflect user_editperms rights in security.pl

thank you,
