1. Allow app (or extension) developer to push new updates to the users without the consent of the users.
2. Not allow the app (or extension) developer to push malicious/dangerous updates.
I would prefer a system where all extensions that are installable by default without jumping through hoops are hand-reviewed by the same people who package my browser for me.
I generally oppose automatic updates and granting app/extension developers the ability to push code to my computer without my consent. I support a walled garden controlled by benevolent package maintainers.
This is where I think the traditional Linux package maintainer shines, protecting the user from malicious software. If a package-maintainer (generally independent from the developer) packages software for a Linux distro, the package-maintainer can drop harmful updates. If instead we give the developers free-reign to push updates without user consent, the developers can and will sell out to the highest bidder.