[eluser]Dam1an[/eluser]
[quote author="bargainph" date="1241667935"][quote author="Dam1an" date="1241659204"]thats largely the developers fault[/quote]
Yeah blame it on them!
[/quote]
If you don't check a user has the permissions to delete stuff they shouldn't, its your fault.
If you code around you're own API (which does the checks) because you made the model method public, then its also your fault