The underlying code is already documented as requiring appropriate RBAC
control, but adding a forced user opt-in to make sure that users
that don't read documentation are still aware of what's required
from a security perspective.
https://huntr.com/bounties/8f4ad910-7fdc-4089-8f0a-b5df5f32e7c5