Index: chrome/common/chrome_switches.cc |
diff --git a/chrome/common/chrome_switches.cc b/chrome/common/chrome_switches.cc |
index 2210c662f018cfd88fc6c65df8c38fa0fd4e822c..80f18189ca1b48e60950475650d9ea2a95d032ea 100644 |
--- a/chrome/common/chrome_switches.cc |
+++ b/chrome/common/chrome_switches.cc |
@@ -87,6 +87,12 @@ const char kAppsGalleryDownloadURL[] = "apps-gallery-download-url"; |
// confirmation dialog. A value of 'accept' means to always act as if the dialog |
// was accepted, and 'cancel' means to always act as if the dialog was |
// cancelled. |
+// |
+// TODO (rdevlin.cronin): Remove this. |
+// This is not a good use of a command-line flag, as it would be equally |
+// effective as a global boolean. Additionally, this opens up a dangerous way |
+// for attackers to append a commandline flag and circumvent all user action for |
+// installing an extension. |
const char kAppsGalleryInstallAutoConfirmForTests[] = |
"apps-gallery-install-auto-confirm-for-tests"; |