{"version":"2.1.280","anchor":"path-outside-boundary-denial-messages-now-include-the-resolv","canonical_anchor":"path-outside-boundary-denial-messages-now-include-the-resolv","heading":"Path-outside-boundary denial messages now include the resolved landing path","tier":"notice","area":"Permissions","scope":null,"heads_up":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/path-outside-boundary-denial-messages-now-include-the-resolv","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### Path-outside-boundary denial messages now include the resolved landing path\n\nPermission-denial messages for paths that escape an allowed folder now show where the path actually ends up\n\n**What**\n\nWhen a file path resolves, via a symlink or `..` traversal, to somewhere outside a folder Claude Code is allowed to access, the denial message and the blocked path it reports now show the actual resolved landing location rather than the original path string as typed. The permission-denial builder also now checks for an unresolved-path case first.\n\n**Why**\n\nThis makes it clearer why a permission was denied, since the reader can see exactly where a seemingly-safe path actually pointed, rather than just the path they entered.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}