It's also possible that the reply link is listed in the page source somewhere, even if you aren't logged in, but hidden by some function or stylesheet instruction, which would mean that a bot might be able to generate a reply page. The submit action is on that page in that case, but the db requires authorisation to complete the request.
I'm reasonably sure the explanation includes this sort of thing.
The alternative would be for a bot to generate likely URLs when crawling a page, but I think that is a long shot.