It’s not that adding the bit is difficult … it’s the dual maintenance. What if my “belief” that the user has DM access somehow gets out of sync with Twitter’s belief? In fact, this has happened already. Some of my users entered my service AFTER the change was made, so a number of them have DM and I don’t know who.
I’ll guess try the “DM feed load” hack. As for this being an exception vs. norm … we’re talking about authentication and authorization, this is the MOST important thing! If I’m having trouble getting users in the door, all the other bells and whistles don’t really matter.