The idea is to implement a Velocity uberpector which would rely on an annotation to tell it which right an author should have to be allowed to call a Java method.
It was the intent of XWIKI-2180 but was only partially done (there was no check at all) and it was too restrictive.