What
- The core read/write permission-decision function now takes a richer path-resolution object with a
spellingsset and anunresolvedflag; when a path's symlink chain can't be resolved, it now explicitly denies with a dedicated reason instead of silently falling through, and still honorsblockReadsOutsideWorkingDirectoriesand restricted-mode circuit breakers. - The permission stash used for later prompt dedup/matching now stores the path's
spellingsset instead of the whole path-resolution object. checkPermissionsfor the Edit and NotebookEdit tools no longer returns the base permission decision directly; it now only short-circuits on an explicit deny, and otherwise runs an extra check against the stashed path/spellings that can override an allow/ask decision.
Why
This closes a gap where a path whose symlink chain couldn't be resolved could otherwise be treated as safe, and makes sure Edit/NotebookEdit re-check the resolved path before allowing an operation.
Names in the bundleblockReadsOutsideWorkingDirectories
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Added since
A small documentation edit on Configure permissions touched a line naming blockReadsOutsideWorkingDirectories after this was published.
Claude Code recognizes a built-in set of Bash commands as read-only and runs them without a permission prompt in every mode, except for a path that [`permissions.blockReadsOutsideWorkingDirectories`](/docs/en/settings-reference#permissions…permissions see the edit
Confirmed since
Anthropic's documentation has since written up blockReadsOutsideWorkingDirectories, on Claude Code changelog.
* Added Claude apps gateway support for newer Claude Desktop keys in `desktop` policy blocks, including `blockReadsOutsideWorkingDirectories` and `disableBypassPermissionsMode`changelog see the edit
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agrees
Anthropic's documentation has since written up blockReadsOutsideWorkingDirectories, on Claude Code changelog.