With the new "allow no password inside LAN" option would it be hard to add a "Allow/disallow remote access" option for each user.
To prevent unauthorized access I would prefer to lock down who can login remotely. This was posted in feature requests previously but can do again if you like.