It looks like connection.php from Flashchat forces no authentication for administrative actions, just the magic URL.