Don’t forget, repeatedly ignoring the requirements for including tests, and instead offering up a “have tested it locally, trust me” as a substitute.
The worry here is that they need to leave the security hole open because they're using it?
The worry here is that they need to leave the security hole open because they're using it?