This is a quote from DHH from LinkedIn:
>Of course we gave them a login. We’ve been publishing apps on the App Store for over a decade. This was not a low-level mistake. It went all the way to the app review board.
In another response he writes that the reviewers did in fact log in.