The extension needs to work on claude.ai/code like every other site;
the user toggles it off manually when needed. Dropping the host-level
skip leaves the word-boundary mapping fix as the only behavior change
on this branch.
https://claude.ai/code/session_01Y2YprLMx348eWD5C9Z4zpV
Drops the narrow field-based walker. Matching only known user-input
fields is brittle: the moment Anthropic renames prompt/input/messages
the walker silently stops substituting and real data leaks.
Preferring robustness over convenience here — the extension stays
dormant on claude.ai/code regardless of future API shape changes, and
users handle redaction manually on that one app. The word-boundary
mapping fix from the previous commit is unaffected.
https://claude.ai/code/session_01Y2YprLMx348eWD5C9Z4zpV
Replaces the blanket skip on claude.ai/code with a targeted walker so
the user's prompt and pasted attachments still get substituted, but
tool_use / tool_result / system / IDs / metadata pass through verbatim.
Fields touched:
- top-level prompt and input (classic claude.ai shape)
- attachments[].extracted_content and attachments[].file_name
- messages[].content (or text parts) when role === 'user'
FormData uploads continue to flow through DocumentScanner since they
are user input. Raw non-JSON bodies are skipped on this path because
they are typically tool traffic, not user text.
https://claude.ai/code/session_01Y2YprLMx348eWD5C9Z4zpV
Two user-reported conflicts when using the extension alongside Claude
Code on the web and with short mappings:
1. Claude Code (claude.ai/code) sends real file paths, usernames, and
shell commands to its tool runtime. Substituting any of these
corrupts execution, forcing users to disable the extension for that
app. early-hook.js and injector.js now short-circuit on that path so
fetch/XHR are never wrapped and no page-world script is injected.
2. Explicit mappings used raw literal regexes, so "not" -> "bad" would
rewrite "nothing" into "badhing". substitute/reveal/scan/diff (and
their page-world mirrors) now add \b on word-character edges only,
leaving non-word edges like "@foo" unchanged so they keep matching.
https://claude.ai/code/session_01Y2YprLMx348eWD5C9Z4zpV
The plus button handler in the pre-send PII warning had two bugs:
1. It read/wrote mappings directly via the storage bridge (api.storage.local),
bypassing the Storage module's encryption layer. When at-rest encryption was
enabled, getStorageData returned an encrypted blob instead of an array,
causing .push() to throw a TypeError that silently aborted the handler —
the mapping was never saved and replaceInInput never ran.
2. Unlike the ignore button which immediately removes the DOM item, the plus
button relied on a re-scan at 150ms to dismiss the notification. If
replaceInInput didn't stick (e.g. React-controlled inputs), the re-scan
found PII again and the notification persisted.
Fix: Route mapping creation through the background service worker via a new
'add:mapping' message handler (which uses Storage.addMapping with proper
encryption support), and immediately dismiss the notification item from the
DOM like the ignore button does.
https://claude.ai/code/session_01RfzvB5sHah326acr8Xa7Jn
Two related races caused substitution to silently fail with at-rest encryption:
1. vault:request-unlock was sent at the top of init(), but the runtime.onMessage
listener that handles the vault:unlocked response was registered only after
await-ing the document-scanner script. A warm service worker (e.g. freshly
woken by a sync operation) could respond before the listener existed, dropping
the message permanently.
2. Even if the listener was registered in time, it posted to window immediately,
but content.js hadn't been injected yet, so its window.addEventListener('message')
handler wasn't live and the message went nowhere.
Fix: register api.runtime.onMessage before injecting content.js, and move the
vault:request-unlock send into script.onload — by that point content.js has fully
executed and its message listener is live.
Also stop passing the encrypted settings blob as initial config. When isLocked,
ss_settings is { _ssLocalEncrypted: true, data: '...' }; passing it to content.js
as the initial settings object clutters the settings with encrypted garbage.
Now falls back to { enabled: true } like mappings/identity already did.
https://claude.ai/code/session_01CwcZK8nqL8pyBH9AxDs9qo
When at-rest encryption is enabled, injector.js detects encrypted blobs
in storage, passes empty config to the content script, and waits for a
vault:unlocked broadcast from the background. That broadcast was only
ever triggered when the user explicitly entered their password in the
popup. After a Gist/URL sync import (which writes newly-imported data
in encrypted form), no page ever received the decrypted config, so
substitution silently stopped working.
Two fixes:
1. injector.js: when isLocked is true (encrypted blobs detected), send
vault:request-unlock to the background. If the key is already cached
(e.g. the user authenticated during the sync pull), the background
responds immediately with vault:unlocked containing the decrypted
data. This fixes every new page load after a sync import.
2. service-worker.js: add vault:request-unlock handler that checks
Storage.isLocked() and, if the key is available, reads decrypted
mappings/identity/settings and sends vault:unlocked back to the
requesting tab.
3. options.js: after a successful Gist or URL pull, send vault:unlocked
to the background so it broadcasts decrypted data to all currently-
open tabs immediately, without requiring a page reload.
https://claude.ai/code/session_01QJnEnLfbXKR5FSCQ3Qfs53
- Inject document-scanner.js into page world via injector.js (as module,
sets globalThis.DocumentScanner)
- Add FormData interception to fetch hook: scans File/Blob entries through
DocumentScanner.processUpload(), also substitutes string fields
- Add document-scanner.js to web_accessible_resources in both manifests
- Bump version to 0.9.23 in package.json, manifest.json, manifest.firefox.json
https://claude.ai/code/session_01NNBEPuXMFGWezJb1f958nL
Going back to a known-good baseline. This version had:
- Working reveal mode with CSS Highlight API
- Working substitution (fetch + XHR hooks)
- Smart patterns (names, emails, phones, usernames)
- Encryption/sync (password, TOTP, WebAuthn)
- Multiple identity profiles
- Activity log
- Secret scanner
- Auto-detect PII warnings
- Pre-send PII detection
Kept current manifests (UUID, data_collection_permissions, version).
No renames applied — uses original naming (secretScanning, PPI, etc).
Will re-apply renames and new features from this working base.
https://claude.ai/code/session_01KF4i7Ra7zCEDskxDBaNtcT
The data-ss-config attribute on the script tag was being removed
(via script.onload) before content.js could read it. Changed approach:
inject config as a separate <script type="application/json" id="ss-config-data">
element that persists in the DOM until content.js reads and removes it.
This eliminates the race condition between script execution and onload
removal. Bump 0.9.20.
https://claude.ai/code/session_01KF4i7Ra7zCEDskxDBaNtcT
Restored injector.js from v2.0.14 (commit 9a11896) which:
- Requests decrypted config from background via get:decrypted-config
message instead of passing empty arrays when data is encrypted
- Handles the identity.profiles merge correctly for background responses
- Passes ss_settings directly (not checking _ssLocalEncrypted which
caused settings loss)
Added missing get:decrypted-config message handler to service-worker.js
which returns decrypted mappings, identity, and settings via Storage
module.
https://claude.ai/code/session_01KF4i7Ra7zCEDskxDBaNtcT
When at-rest encryption is enabled, storage.onChanged fires with
encrypted blobs for ss_settings. The injector was passing this
encrypted blob directly as settings to the page world content script,
overwriting real settings with { _ssLocalEncrypted: true, data: ... }.
This broke reveal mode, highlights, and any setting toggle because
the content script's settings object became the encrypted blob.
Fix: skip encrypted settings blobs in injector.js (same check already
existed for mappings and identity). The background's settings:updated
message already sends decrypted settings correctly.
https://claude.ai/code/session_01KF4i7Ra7zCEDskxDBaNtcT
Bug 1: popup.html had duplicate id="optAutoRedact" on both the
Auto Redact toggle and Auto-redact Detected PII toggle. The second
overwrote the first, making the Auto Redact setting uncontrollable.
Fixed by giving the second toggle id="optAutoRedactDetected".
Bug 2: injector.js hardcoded activity log trim to 100, ignoring the
user's maxLogEntries setting. Now reads the setting from storage.
Added test-suite.html with 35+ tests covering storage, encryption,
sync (encryption-mandatory flows), auto-redact (built-in + custom
patterns), substitution engine, smart patterns, and auto-detect.
https://claude.ai/code/session_01KF4i7Ra7zCEDskxDBaNtcT
Sync operations (browser sync, Gist, custom URL, sync code) now refuse to
operate without encryption enabled. Disabling encryption also turns off all
active sync channels. Activity log cap reduced from 200 to 100 entries for
both storage and display.
https://claude.ai/code/session_01KF4i7Ra7zCEDskxDBaNtcT
All sensitive data (identity, mappings, activity log) is now AES-256
encrypted in browser.storage.local when sync encryption is enabled.
TOTP secret is also encrypted at rest using the derived key.
Vault unlock flow:
- On browser restart, extension detects locked state (encrypted data,
no cached CryptoKey) and shows LOCK badge in red
- Popup shows a full-screen unlock prompt with password field,
optional TOTP, and biometric button
- After unlock, background decrypts and broadcasts data to all tabs
- Content scripts start with empty config when locked; receive
decrypted config via vault:unlocked message after unlock
- Injector skips encrypted blobs in storage change events
Storage module changes:
- _readSecure / _writeSecure transparently encrypt/decrypt
- encryptExistingData() migrates plaintext → encrypted on setup
- decryptAllData() restores plaintext when encryption is disabled
- isLocked() checks for encrypted data + missing key
https://claude.ai/code/session_01SWSwDfMVij53bCTNSCLMwn
Like spellcheck for privacy. Scans text as you type and paste
into chat inputs (debounced 800ms). Shows a dark floating warning
panel listing detected PPI BEFORE you hit Enter.
Each detected item has a green [+] button that instantly:
1. Generates a plausible fake value (random IP, fake address, etc.)
2. Adds it as a mapping to storage
3. Shows a checkmark to confirm
The warning disappears when you clear the text or when all
detected items have been addressed.
Three new Options toggles:
- Auto-detect unconfigured PPI (on by default)
- Offer to auto-add detected PPI (on by default)
Also adds a storage bridge (postMessage) so the page-world
content script can read/write chrome.storage through the
injector.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
After the multi-profile migration, ss_identity changed from a flat
object { names, emails, ... } to { profiles: [...] }. The injector
was passing the raw profiles wrapper to the content script, which
expected the flat format.
Now the injector merges active profiles into a flat identity object
before injecting into the page world, and also merges on storage
change events. Also handles legacy format (pre-profile data) for
backward compatibility.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Activity log fix:
- Injector now writes directly to storage.local in addition to
sending runtime messages to the background worker. This fixes
the issue where MV3 service worker sleep caused messages to be
silently dropped.
Dynamic icon colors:
- Black "SS" = active, normal
- Blue "SS" = reveal mode on
- Red "SS" = Silent Send disabled
- Icons generated via OffscreenCanvas in the service worker
- Updates on every settings change and keyboard shortcut toggle
Also adds keyboard shortcuts section to Options page showing
current bindings and how to customize them per browser.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
- Add custom domain support in Options page so users can add
self-hosted AI services (e.g. https://ai.myserver.com)
- Background worker dynamically injects content scripts on
custom domains using scripting.executeScript
- Add optional_host_permissions so Chrome can grant per-domain access
- Rewrite README: add clone step to Firefox instructions, clarify
what "credentials" means in step 3, add Windows commands alongside
Mac/Linux for every terminal step
- Bump version to 0.2.0
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Instead of requiring explicit mappings for every variation, users
now configure their identity once (Identity tab) and Silent Send
auto-catches:
- Emails: any address @gmail, @yahoo, @outlook, etc.
- Names: first/last, full name, reversed, possessives, case variants
- Usernames: user@host, ~user, /home/user, C:\Users\user
- Phones: all common formats ((555) 123-4567, 555.123.4567, etc.)
Smart patterns run before explicit mappings, so explicit rules
can override smart catches when needed.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Add manifest.firefox.json for Firefox MV3 (gecko ID, background
scripts instead of service_worker, options_ui). Introduce
browser-polyfill.js shim so all modules use whichever API is
available (browser.* or chrome.*). Add build.sh to target
chrome, firefox, or both.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw
Chrome Manifest V3 extension that intercepts personal data and
substitutes it with user-defined replacements before sending to
Claude.ai. Hooks fetch() in the page's main world to catch API
requests, with bidirectional substitution (real→fake on send,
fake→real on display via reveal mode).
Includes popup UI with mapping management, live test/diff view,
activity log with badge count, options page with import/export,
and Shadow DOM traversal for Claude.ai compatibility.
https://claude.ai/code/session_01Dvgwe7XMoSxnWXkih8p1Cw