Who owns this secret? Nobody. Great, that's me: deleting secrets in Password Pusher
An unauthenticated visitor holding only a Password Pusher link could permanently destroy the secret behind it, even with deletable_by_viewer turned off, because the ownership check compared two nils and Ruby said they matched.