mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-09-21 08:02:38 +00:00
Any Read() deny rule makes Claude Code resolve the file operands of every Bash command that reads files. A path it cannot resolve, such as one that follows a cd into a directory the analyzer does not track, escalates to a permission prompt even under bypassPermissions. A plain recursive grep in the repo root escalates too, because it could reach .env. Drop the read rules and widen the write rules to cover the same files, so secrets still cannot be written through Edit, Write, or a shell redirect. Reads of those files are no longer blocked. Claude-Session: https://claude.ai/code/session_01RNCupPk2yewQT1JMNjkV8M Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
150 lines
4.0 KiB
JSON
150 lines
4.0 KiB
JSON
{
|
|
"permissions": {
|
|
"additionalDirectories": [
|
|
"../windmill-ee-private"
|
|
],
|
|
"allow": [
|
|
"Bash(ls:*)",
|
|
"Bash(grep:*)",
|
|
"Bash(cat:*)",
|
|
"Bash(head:*)",
|
|
"Bash(tail:*)",
|
|
"Bash(less:*)",
|
|
"Bash(more:*)",
|
|
"Bash(find:*)",
|
|
"Bash(wc:*)",
|
|
"Bash(diff:*)",
|
|
"Bash(file:*)",
|
|
"Bash(stat:*)",
|
|
"Bash(tree:*)",
|
|
"Bash(pwd)",
|
|
"Bash(which:*)",
|
|
"Bash(whereis:*)",
|
|
"Bash(echo:*)",
|
|
"Bash(git status:*)",
|
|
"Bash(git diff:*)",
|
|
"Bash(git log:*)",
|
|
"Bash(git branch:*)",
|
|
"Bash(git show:*)",
|
|
"Bash(git blame:*)",
|
|
"Bash(cargo check:*)",
|
|
"Bash(cargo build --release:*)",
|
|
"Bash(sh wm-ts-nav/nav:*)",
|
|
"Bash(wm-ts-nav/nav:*)",
|
|
"Bash(./wm-ts-nav/nav:*)",
|
|
"Bash(wm-ts-nav/target/release/wm-ts-nav:*)",
|
|
"Bash(./wm-ts-nav/target/release/wm-ts-nav:*)",
|
|
"mcp__ide__getDiagnostics",
|
|
"Bash(npm run generate-backend-client:*)",
|
|
"Bash(npm run check:*)",
|
|
"Bash(git push:*)",
|
|
"Bash(git reset:*)",
|
|
"Bash(git revert:*)",
|
|
"Bash(git checkout:*)",
|
|
"Bash(git merge:*)",
|
|
"Bash(git rebase:*)",
|
|
"Bash(git add:*)",
|
|
"Bash(git commit:*)",
|
|
"Read(/tmp/**)",
|
|
"Write(/tmp/**)",
|
|
"Edit(/tmp/**)",
|
|
"mcp__claude_ai_Gmail__search_threads",
|
|
"mcp__claude_ai_Gmail__get_thread",
|
|
"mcp__claude_ai_Gmail__get_message",
|
|
"mcp__claude_ai_Gmail__list_labels",
|
|
"mcp__claude_ai_Gmail__list_drafts"
|
|
],
|
|
"deny": [
|
|
"Edit(.env)",
|
|
"Edit(.env.*)",
|
|
"Edit(**/.env)",
|
|
"Edit(**/.env.*)",
|
|
"Edit(**/secrets/**)",
|
|
"Edit(**/*.pem)",
|
|
"Edit(**/*.key)",
|
|
"Edit(**/credentials.json)",
|
|
"Edit(**/.secret*)",
|
|
"Edit(**/.secrets*)",
|
|
"Edit(**/*.secret)",
|
|
"Edit(**/*.secrets)"
|
|
],
|
|
"ask": [
|
|
"Bash(rmdir:*)",
|
|
"Bash(chown:*)",
|
|
"Bash(truncate:*)",
|
|
"Bash(shred:*)",
|
|
"Bash(unlink:*)",
|
|
"mcp__claude_ai_Stripe",
|
|
"mcp__claude_ai_Gmail__create_draft",
|
|
"mcp__claude_ai_Gmail__update_draft",
|
|
"mcp__claude_ai_Gmail__create_label",
|
|
"mcp__claude_ai_Gmail__label_message",
|
|
"mcp__claude_ai_Gmail__label_thread",
|
|
"mcp__claude_ai_Gmail__unlabel_message",
|
|
"mcp__claude_ai_Gmail__unlabel_thread",
|
|
"mcp__claude_ai_Gmail__apply_sensitive_message_label",
|
|
"mcp__claude_ai_Gmail__apply_sensitive_thread_label",
|
|
"mcp__claude_ai_Google_Calendar",
|
|
"mcp__claude_ai_Google_Drive",
|
|
"mcp__claude_ai_Slack",
|
|
"mcp__claude_ai_Linear"
|
|
]
|
|
},
|
|
"enableAllProjectMcpServers": true,
|
|
"hooks": {
|
|
"PreToolUse": [
|
|
{
|
|
"matcher": "Bash",
|
|
"hooks": [
|
|
{
|
|
"type": "command",
|
|
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/guard-main-branch.sh",
|
|
"timeout": 5
|
|
},
|
|
{
|
|
"type": "command",
|
|
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/guard-rm-outside-tmp.sh",
|
|
"timeout": 5
|
|
},
|
|
{
|
|
"type": "command",
|
|
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/allow-fileops-in-tmp.sh",
|
|
"timeout": 5
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"PostToolUse": [
|
|
{
|
|
"matcher": "Edit|Write",
|
|
"hooks": [
|
|
{
|
|
"type": "command",
|
|
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/format-frontend.sh",
|
|
"timeout": 30
|
|
},
|
|
{
|
|
"type": "command",
|
|
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/format-backend.sh",
|
|
"timeout": 30
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"Notification": [
|
|
{
|
|
"hooks": [
|
|
{
|
|
"type": "command",
|
|
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/notify-user.sh",
|
|
"timeout": 10
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"enabledPlugins": {
|
|
"typescript-lsp@claude-plugins-official": true,
|
|
"code-review@claude-plugins-official": true
|
|
}
|
|
} |