Comment #11 on issue 27431 by [email protected]: Special extension install mode for gallery http://code.google.com/p/chromium/issues/detail?id=27431
Lei mentioned last week that silent install would not be in beta install. Regarding the site, - I don't believe the port to Django auto-escaping is done yet. - Also, it might be good to add some form of XSRF token for download that ensures that request to download link came from chrome.google.com/extensions if there will be silent install - currently I can directly link the download such as: https://clients2.google.com/service/update2/crx? response=redirect&x=id%3Dmihcahmgecmbnbcchbopgniflfhgnkff%26uc%26lang%3Den- US&prod=chrome&prodversion=4.0.212.0 which gets redirected to cookieless domain. eg: https://clients2.googleusercontent.com/crx/download/OAAAAAuGYvDZad6jSIbsNlC7GOFAMhquo DgunpOlDXpXk30K90zgtNGEuLg2sDirQHeebW7- 55CDqQCT07IBM2noYokAxlKa5bUeE_60GlustmP_s9GVP_hQnWHt/extra_1_0.crx Agree that it would be nice to add STS. Chris, I was not able to access chrome.google.com/extras from www.google.com. Which server were you referring to? -- You received this message because you are listed in the owner or CC fields of this issue, or because you starred this issue. You may adjust your issue notification preferences at: http://code.google.com/hosting/settings -- Automated mail from issue updates at http://crbug.com/ Subscription options: http://groups.google.com/group/chromium-bugs
