fix: config not reaching content.js — race condition with script removal

The data-ss-config attribute on the script tag was being removed
(via script.onload) before content.js could read it. Changed approach:
inject config as a separate <script type="application/json" id="ss-config-data">
element that persists in the DOM until content.js reads and removes it.

This eliminates the race condition between script execution and onload
removal. Bump 0.9.20.

https://claude.ai/code/session_01KF4i7Ra7zCEDskxDBaNtcT
This commit is contained in:
Claude
2026-03-29 18:25:28 +00:00
parent b622d5abd4
commit 740f692ff1
6 changed files with 16 additions and 7 deletions
+1 -1
View File
@@ -1,7 +1,7 @@
{
"manifest_version": 3,
"name": "Silent Send",
"version": "0.9.19",
"version": "0.9.20",
"description": "Intercepts personal info and substitutes it with user-defined replacements before sending to AI services.",
"browser_specific_settings": {
"gecko": {
+1 -1
View File
@@ -1,7 +1,7 @@
{
"manifest_version": 3,
"name": "Silent Send",
"version": "0.9.19",
"version": "0.9.20",
"description": "Intercepts personal info and substitutes it with user-defined replacements before sending to AI services.",
"permissions": [
"storage",
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "silent-send",
"version": "0.9.19",
"version": "0.9.20",
"private": true,
"license": "MIT",
"description": "Browser extension that substitutes personal data before sending to AI services",
+3 -2
View File
@@ -26,12 +26,13 @@
let settings = { enabled: true, revealMode: false, showHighlights: false };
try {
const configEl = document.querySelector('script[data-ss-config]');
const configEl = document.getElementById('ss-config-data');
if (configEl) {
const config = JSON.parse(configEl.getAttribute('data-ss-config'));
const config = JSON.parse(configEl.textContent);
mappings = config.mappings || [];
identity = config.identity || {};
settings = { ...settings, ...(config.settings || {}) };
configEl.remove(); // clean up
}
} catch (e) {
console.warn('[Silent Send] Failed to parse initial config:', e);
+9 -1
View File
@@ -97,9 +97,17 @@
identity = mergeProfiles(identity);
}
// Inject config as a global variable before loading content.js
// Using a separate inline-data element ensures content.js can read it
// even if there's a race condition with script.onload removal
const configEl = document.createElement('script');
configEl.type = 'application/json';
configEl.id = 'ss-config-data';
configEl.textContent = JSON.stringify({ mappings, identity, settings });
(document.head || document.documentElement).appendChild(configEl);
// Inject the main interception script into the page's world
const script = document.createElement('script');
script.setAttribute('data-ss-config', JSON.stringify({ mappings, identity, settings }));
script.src = api.runtime.getURL('src/content/content.js');
(document.head || document.documentElement).appendChild(script);
script.onload = () => script.remove();
+1 -1
View File
@@ -629,7 +629,7 @@
</section>
<footer>
<p>Silent Send v0.9.19</p>
<p>Silent Send v0.9.20</p>
<p style="font-size:11px;color:#9ca3af;margin-top:6px;max-width:600px">
Silent Send is a convenience tool, not a security guarantee. Third-party sites may change how they send data at any time, which can cause missed substitutions without warning. You are responsible for verifying your data before sending. See the <a href="https://github.com/outis1one/silent-send/blob/main/LICENSE" target="_blank" style="color:#6b7280">LICENSE</a> for full terms.
</p>