Hi Florian,
currently there is neither a spi for writing own restxq annotations (or annotations processing in general) nor a specfication for annotations concerning a security aspect. But i'm working on exactly these both issues. There is a site in the BaseX wiki for collecting use cases/requirements/... for the security annotation specification (http://docs.basex.org/wiki/Security:_Use_Cases) and it would be really nice to get youre input and ideas to find a solution which is applicable for youre webapplication and also for webapplication in general.
Regards, Marcel