What's wrong with this entry?
The mTLS client certificate implementation was refactored to support hot-reloading. Previously, certificates were loaded once at startup (via a singleton). Now:
- Certificates are re-read from disk whenever
CLAUDE_CODE_CLIENT_CERTorCLAUDE_CODE_CLIENT_KEYchanges - An async reload function queues sequential refreshes (no concurrent reloads)
- The HTTPS agent is rebuilt only when the certificate content actually changes
- Path and content are both tracked to detect file replacement vs. content changes
Error messages are now more descriptive, reporting the certificate role (e.g., "client certificate from CLAUDE_CODE_CLIENT_CERT") rather than the file path.
Refactored mTLS module (search for "mTLS: Loaded client certificate from CLAUDE_CODE_CLIENT_CERT", "mTLS: Creating HTTPS agent with custom certificates")
Strings lifted out of the shipped bundle, so the claim above can be checked against them.