{"version":"2.1.268","anchor":"strict-network-allowlist-check-consolidated-and-extended-wit","canonical_anchor":"per-command-sandbox-network-allowlist-can-now-be-looked-up-a","heading":"Sandbox network allowlist gains per-command rules and consolidated strict-allowlist checks","tier":"notice","area":"Sandbox Network","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.268\/e\/strict-network-allowlist-check-consolidated-and-extended-wit","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.268","markdown":"### Sandbox network allowlist gains per-command rules and consolidated strict-allowlist checks\n\nSandbox network permission checks can now allow specific commands extra domains and give clearer denial reasons\n\n**What**\n\n- A new per-command allowlist map is checked after the global `strictAllowlist`\/config rules fail, letting a specific command's own `allowed_domains` grant network access (\"Allowed by per-command rule\"). A companion UI formatter shows these as \"Also lets this command reach, beyond the sandbox allowlist: ...\" with long host lists truncated at 160 characters.\n\n- The network-permission gate now consults this per-command allowlist (looked up by an origin key) after global config rules but before falling back to strict-allowlist denial, and the strict-allowlist short-circuit was reordered to run earlier. User-denial callbacks can now return an object with a custom `reason` string instead of just true\/false.\n\n- The strict network allowlist check (`sandbox.network.strictAllowlist`) was consolidated into a single helper that replaces an inline chain, and a related combined check now also factors in the `CLAUDE_CODE_EVAL_CONFINED` environment variable to decide whether allowed domains should be forced empty.\n\n**Why** This lets individual commands be granted extra network access beyond the sandbox's global allowlist, gives clearer explanations when network access is denied, and tightens how the strict-allowlist and eval-confinement settings interact.\n\n- Area: Sandbox Network\n- Names: `sandbox.network.strictAllowlist`, `CLAUDE_CODE_EVAL_CONFINED`\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 2\/5"}