If the ACLs level permissions are not working, you can create a group and add the user to that group
Also implement a sling filter which checks only for that path and also check the current use belongs to the group, if use user is present in that group then forward the request else Reject the reques...