I think it has less to do with ORM and more to do with laziness. Its really one line in the controller, if loggedin user is not the user trying to edit redirect.
It's not just laziness. 99% of all framework tutorials I've seen out there completely ignores even basic authentication/authorization issues, which are universal to all real websites. This lack of attention to details is cultivated.
I guess they are using Rails. If they had only taken a few hours to go through a free tutorial like the one at railstutorial.org , they could have avoided this blunder.