1.1.all important data is a resource2. every resource has a proper name (URL)
2.:format (that period is a concatenation period)
3.the method within the controller to call
4. 1. login method (that checks a username and password) and 2. a filter (that calls the login method when needed)