Your credentials file is now read with symlink and size protections and written owner-only.
What's wrong with this entry?
The plaintext credentials file (.credentials.json in the credential store directory) is now opened with O_NOFOLLOW and non-blocking mode, reports a distinct refused-symlink result when the path is a link, treats directories and files above a size cap as corrupt, and is written with mode 0600.
- A probe returns a version string built from device, inode, size and modification time in nanoseconds, so callers can detect changes without re-reading.
- A strict read variant treats permission errors as "file absent" only on non-Windows platforms.
- The store handle is handed out only when the secure-storage check passes.
refused-symlink
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.242
Session spawn aborts on host-specific write paths committed to a repo
Both mention json
-
v2.1.247
Warning when
~/.claude.jsoncannot be watched for outside editsBoth mention json
-
v2.1.224
Invalid sandbox credential settings now fail closed instead of being ignored
Both mention credential