It allows you to grief the users of any rails site. You can log them out at will (for some value of at will).
In the dawn of time, you could use a CSRF exploit and really grief the users. Then CSRF checking made that go away. This is now a step backwards, where 3rd party sites can affect your users.