That's an interesting idea, but - where is authorization for node accesses done? If it happens on the development server (and I don't see how you could feasibly do it elsewhere, ie on the live site), anyone who can apply patches can patch the authorization code and so grant himself full access..