Serious question: how is that any different than leaving SQL injection points in place and then just documenting it?
What Rails have done is to have a particular default (whose correctness can be debated) and document how it can be exploited and how to safeguard from it.