nested/coupled <who> clauses in ACLs

Let's say that I want to make a group of entries accessible to anonymous,
but only when it is connecting from localhost. EG:

  access to <foo>
    by anonymous(peername.ip=   read
    by *                                  none

Is this supported or available through some kind of trickery?

I can't find any documentation that allows this.

Eric A. Hall                                        http://www.ehsco.com/
Internet Core Protocols          http://www.oreilly.com/catalog/coreprot/