If a user is signed in they can access the edit page/form for any post created on the form. While they can't "PATCH", or at least I'm not going to mess with the header token, the post. This can lead to someone with time causing problems.
Also on the CONTRIBUTOR POST the link for:
"How to contribute as A GRAPHIST"
links to the edit page not the show page, kind of how i discovered this