A green extension badge is not a test result. Before sharing a browser, use a small fixture that exercises the places where redaction commonly fails.
Five cases
- Static text: invented email, phone and API-key-shaped values. Never use a real credential in the fixture.
- Dynamic DOM: content inserted after load, a filtered table, or a client-side route change.
- Inputs: a prefilled settings field and a value typed while the field has focus.
- Non-text visuals: a chart, map, canvas or avatar that needs a manual blur region.
- Emergency control: the full-page panic shortcut, tested before the call.
Add one negative case: a harmless value that must remain visible. False positives can make a demo unreadable and encourage people to disable protection entirely.
Rehearse persistence
Reload the page, change zoom, resize the window and move between records. If you use a manual region, confirm that it still covers the intended widget. If you add a custom regex, test both matches and near misses.
Auto Blur is a Chromium extension that detects emails, phone numbers, API keys, JWTs, AWS credentials, card numbers, private keys, GitHub tokens, passwords and other secret-shaped values. It also supports input scanning, custom regex rules, manual blur boxes, per-site controls and a panic shortcut. The product says page detection runs locally and page content is not uploaded for classification.
Verify the shared view
A redaction extension works inside the page. Your screen share may also expose the address bar, tab titles, notifications and other browser chrome. Rehearse the exact route and inspect the actual shared surface.
The useful standard is not “the extension is on.” It is “the five-case fixture passed, the real route was rehearsed, and the final shared view was checked.”
Top comments (0)