Index: chrome/common/chrome_switches.cc |
diff --git a/chrome/common/chrome_switches.cc b/chrome/common/chrome_switches.cc |
index c45431eab5738b5d541fb300b000f920254a1a95..6699baf12b363508b3f24697abc171e213dd0c0c 100644 |
--- a/chrome/common/chrome_switches.cc |
+++ b/chrome/common/chrome_switches.cc |
@@ -87,6 +87,12 @@ const char kAppsGalleryDownloadURL[] = "apps-gallery-download-url"; |
// confirmation dialog. A value of 'accept' means to always act as if the dialog |
// was accepted, and 'cancel' means to always act as if the dialog was |
// cancelled. |
+// |
+// TODO (rdevlin.cronin): Remove this. |
+// This is not a good use of a command-line flag, as it would be equally |
+// effective as a global boolean. Additionally, this opens up a dangerous way |
+// for attackers to append a commandline flag and circumvent all user action for |
+// installing an extension. |
const char kAppsGalleryInstallAutoConfirmForTests[] = |
"apps-gallery-install-auto-confirm-for-tests"; |