s4-drs: fix the logic to allow REPL_SECRET if the account has GET_ALL_CHANGES