Here is a patch for the flag suggested by Stephen
Kennedy. It requires a logged in user before allowing
a page to be edited. They can still totally spoof an
identity of course, but at least there is a username
instead of just a hostname.
Logged In: YES
Superseeded by security.py and the