Author SHA1 Message Date
Claude b9acd6d677 Remove claude.ai/code skip
The extension needs to work on claude.ai/code like every other site;
the user toggles it off manually when needed. Dropping the host-level
skip leaves the word-boundary mapping fix as the only behavior change
on this branch.

https://claude.ai/code/session_01Y2YprLMx348eWD5C9Z4zpV
2026-04-16 18:10:04 +00:00
Claude f55f63c254 Revert claude.ai/code to blanket skip
Drops the narrow field-based walker. Matching only known user-input
fields is brittle: the moment Anthropic renames prompt/input/messages
the walker silently stops substituting and real data leaks.

Preferring robustness over convenience here — the extension stays
dormant on claude.ai/code regardless of future API shape changes, and
users handle redaction manually on that one app. The word-boundary
mapping fix from the previous commit is unaffected.

https://claude.ai/code/session_01Y2YprLMx348eWD5C9Z4zpV
2026-04-16 18:03:36 +00:00
Claude 331b1cb2a2 Narrow claude.ai/code interception to user-input fields
Replaces the blanket skip on claude.ai/code with a targeted walker so
the user's prompt and pasted attachments still get substituted, but
tool_use / tool_result / system / IDs / metadata pass through verbatim.

Fields touched:
- top-level prompt and input (classic claude.ai shape)
- attachments[].extracted_content and attachments[].file_name
- messages[].content (or text parts) when role === 'user'

FormData uploads continue to flow through DocumentScanner since they
are user input. Raw non-JSON bodies are skipped on this path because
they are typically tool traffic, not user text.

https://claude.ai/code/session_01Y2YprLMx348eWD5C9Z4zpV
2026-04-16 17:58:48 +00:00
Claude 16c8275f4e Skip claude.ai/code and use word boundaries for mappings
Two user-reported conflicts when using the extension alongside Claude
Code on the web and with short mappings:

1. Claude Code (claude.ai/code) sends real file paths, usernames, and
   shell commands to its tool runtime. Substituting any of these
   corrupts execution, forcing users to disable the extension for that
   app. early-hook.js and injector.js now short-circuit on that path so
   fetch/XHR are never wrapped and no page-world script is injected.

2. Explicit mappings used raw literal regexes, so "not" -> "bad" would
   rewrite "nothing" into "badhing". substitute/reveal/scan/diff (and
   their page-world mirrors) now add \b on word-character edges only,
   leaving non-word edges like "@foo" unchanged so they keep matching.

https://claude.ai/code/session_01Y2YprLMx348eWD5C9Z4zpV
2026-04-16 16:12:04 +00:00
7 changed files with 52 additions and 23 deletions
+1 -1
View File
@@ -1,7 +1,7 @@
{
"manifest_version": 3,
"name": "Silent Send",
"version": "0.9.47",
"version": "0.9.46",
"description": "Intercepts personal info and substitutes it with user-defined replacements before sending to AI services.",
"browser_specific_settings": {
"gecko": {
+1 -1
View File
@@ -1,7 +1,7 @@
{
"manifest_version": 3,
"name": "Silent Send",
"version": "0.9.47",
"version": "0.9.46",
"description": "Intercepts personal info and substitutes it with user-defined replacements before sending to AI services.",
"permissions": [
"storage",
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "silent-send",
"version": "0.9.47",
"version": "0.9.46",
"private": true,
"license": "MIT",
"description": "Browser extension that substitutes personal data before sending to AI services",
+1 -3
View File
@@ -86,9 +86,7 @@ for attempt in $(seq 1 $MAX_ATTEMPTS); do
echo "=== Attempt $attempt: signing v$NEW_VERSION ==="
# Capture output to check for specific errors
# NODE_OPTIONS forces IPv4 DNS resolution first — Node.js 18+ defaults to IPv6,
# which silently fails when the system can't reach addons.mozilla.org over IPv6.
OUTPUT=$(NODE_OPTIONS='--dns-result-order=ipv4first' npx web-ext sign \
OUTPUT=$(npx web-ext sign \
--no-config-discovery \
--source-dir "$SCRIPT_DIR/dist/firefox" \
--artifacts-dir "$SCRIPT_DIR/dist/firefox-signed" \
+18 -9
View File
@@ -51,8 +51,8 @@
for (const m of sorted) {
if (!m.enabled || !m.real?.trim() || !m.substitute?.trim()) continue;
const escaped = esc(m.real);
const regex = new RegExp(escaped, m.caseSensitive ? 'g' : 'gi');
const pattern = wordBoundary(m.real);
const regex = new RegExp(pattern, m.caseSensitive ? 'g' : 'gi');
let match;
while ((match = regex.exec(result)) !== null) {
replacements.push({
@@ -71,8 +71,8 @@
const sorted = [...maps].sort((a, b) => b.substitute.length - a.substitute.length);
for (const m of sorted) {
if (!m.enabled || !m.real?.trim() || !m.substitute?.trim()) continue;
const escaped = esc(m.substitute);
const regex = new RegExp(escaped, m.caseSensitive ? 'g' : 'gi');
const pattern = wordBoundary(m.substitute);
const regex = new RegExp(pattern, m.caseSensitive ? 'g' : 'gi');
result = result.replace(regex, m.real);
}
return result;
@@ -82,6 +82,15 @@
return str.replace(/[.*+?^${}()|[\]\\]/g, '\\$&');
}
// Add \b only on word-character edges so "not" doesn't match inside "nothing",
// while leaving non-word edges (e.g. "@foo") alone since they self-delimit.
function wordBoundary(str) {
const escaped = esc(str);
const left = /^\w/.test(str) ? '\\b' : '';
const right = /\w$/.test(str) ? '\\b' : '';
return left + escaped + right;
}
// ============================================================
// Smart Pattern Engine (inline for page world)
// ============================================================
@@ -1043,8 +1052,8 @@
const pairs = getRevealPairs();
let result = text;
for (const p of pairs) {
const escaped = esc(p.from);
const regex = new RegExp(escaped, p.caseSensitive ? 'g' : 'gi');
const pattern = wordBoundary(p.from);
const regex = new RegExp(pattern, p.caseSensitive ? 'g' : 'gi');
result = result.replace(regex, p.to);
}
return result;
@@ -1085,9 +1094,9 @@
const pairs = getRevealPairs();
let result = text;
for (const p of pairs) {
const escaped = esc(p.to); // p.to is the real value
const regex = new RegExp(escaped, p.caseSensitive ? 'g' : 'gi');
result = result.replace(regex, p.from); // p.from is the substitute
const pattern = wordBoundary(p.to);
const regex = new RegExp(pattern, p.caseSensitive ? 'g' : 'gi');
result = result.replace(regex, p.from);
}
return result;
}
+18 -8
View File
@@ -23,8 +23,8 @@ const SubstitutionEngine = {
for (const mapping of sorted) {
if (!mapping.enabled || !mapping.real?.trim() || !mapping.substitute?.trim()) continue;
const escaped = this._escapeRegex(mapping.real);
const regex = new RegExp(escaped, mapping.caseSensitive ? 'g' : 'gi');
const pattern = this._wordBoundaryPattern(mapping.real);
const regex = new RegExp(pattern, mapping.caseSensitive ? 'g' : 'gi');
let match;
while ((match = regex.exec(result)) !== null) {
@@ -56,8 +56,8 @@ const SubstitutionEngine = {
for (const mapping of sorted) {
if (!mapping.enabled || !mapping.real?.trim() || !mapping.substitute?.trim()) continue;
const escaped = this._escapeRegex(mapping.substitute);
const regex = new RegExp(escaped, mapping.caseSensitive ? 'g' : 'gi');
const pattern = this._wordBoundaryPattern(mapping.substitute);
const regex = new RegExp(pattern, mapping.caseSensitive ? 'g' : 'gi');
result = result.replace(regex, mapping.real);
}
@@ -73,8 +73,8 @@ const SubstitutionEngine = {
for (const mapping of mappings) {
if (!mapping.enabled || !mapping.real?.trim()) continue;
const escaped = this._escapeRegex(mapping.real);
const regex = new RegExp(escaped, mapping.caseSensitive ? 'g' : 'gi');
const pattern = this._wordBoundaryPattern(mapping.real);
const regex = new RegExp(pattern, mapping.caseSensitive ? 'g' : 'gi');
if (regex.test(text)) {
found.push({
@@ -105,8 +105,8 @@ const SubstitutionEngine = {
for (const mapping of sorted) {
if (!mapping.enabled || !mapping.real?.trim() || !mapping.substitute?.trim()) continue;
const escaped = this._escapeRegex(mapping.real);
const regex = new RegExp(escaped, mapping.caseSensitive ? 'g' : 'gi');
const pattern = this._wordBoundaryPattern(mapping.real);
const regex = new RegExp(pattern, mapping.caseSensitive ? 'g' : 'gi');
let match;
while ((match = regex.exec(original)) !== null) {
@@ -145,6 +145,16 @@ const SubstitutionEngine = {
_escapeRegex(str) {
return str.replace(/[.*+?^${}()|[\]\\]/g, '\\$&');
},
// Wrap an escaped literal in \b only on edges that are word characters,
// so "not" → "bad" matches "not" but not "nothing", while mappings whose
// edges aren't word chars (e.g. "@foo", "foo.com ") still work.
_wordBoundaryPattern(str) {
const escaped = this._escapeRegex(str);
const left = /^\w/.test(str) ? '\\b' : '';
const right = /\w$/.test(str) ? '\\b' : '';
return left + escaped + right;
},
};
// Support both module and content-script contexts
+12
View File
@@ -345,6 +345,18 @@ test('Disabled mapping is skipped', () => {
if (result.text.includes('Alex Demo')) throw 'Disabled mapping should not substitute';
});
test('Mapping matches whole words only', () => {
const result = SubstitutionEngine.substitute('nothing is not a thing, not even this', [
{ real: 'not', substitute: 'bad', enabled: true }
]);
if (result.text.includes('bahing') || result.text.includes('badhing')) {
throw `Should not match inside "nothing", got: ${result.text}`;
}
if (!/\bbad\b/.test(result.text)) {
throw `Should still match standalone "not", got: ${result.text}`;
}
});
// ============================================================
// SMART PATTERNS
// ============================================================