{"version":"2.1.281","anchor":"credential-helper-keys-from-managed-policy-new-machine-admi","canonical_anchor":"credential-helper-keys-from-managed-policy-new-machine-admi","heading":"Groundwork to restrict where credential-helper settings can come from (inert in this build)","tier":null,"area":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/credential-helper-keys-from-managed-policy-new-machine-admi","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Groundwork to restrict where credential-helper settings can come from (inert in this build)\n\nA new filter could limit credential-helper settings to admin-controlled managed settings; it is compiled so nothing is filtered yet\n\n**Unclear.** The finding does not say whether the key-stripping filter is also behind the switched-off check.\n\n**What**\n\nClaude Code now contains a filter for credential-helper settings. A credential helper is a setting that names a command Claude Code runs to fetch a key, a login or a header. The filter covers `apiKeyHelper`, `awsAuthRefresh`, `awsCredentialExport`, `gcpAuthRefresh`, `otelHeadersHelper` and `proxyAuthHelper`.\n\n- Every settings source is now passed through the filter before the sources are merged. The filter can remove these keys from a source that is not allowed to supply them.\n\n- New helpers decide whether managed policy settings (`policySettings`, the settings an administrator deploys) are treated as `machine_admin` or `as_read`. The choice depends on whether the managed source can be written by an ordinary user.\n\n- In `machine_admin` mode, the helper keys are removed from the other sources and re-read only from admin-only sources. Remotely delivered settings and MDM sources (device-management profiles) that a user can write to are left out.\n\n- A helper is disabled if it was armed from a remote source or from a user-writable base. The new `helperArmedFromUserWritableBase` check tracks the second case.\n\n- In this build, the switch that picks the mode always returns `as_read`. The live settings loader also hard-codes `credentialHelperKeysFrom: () => \"as_read\"`. As a result, no keys are removed yet.\n\n**Why**\n\nNothing changes for you today, because settings are still merged exactly as read. The code is built so that, once it is switched on, a credential helper command can come only from managed settings an administrator controls, and not from a settings file an ordinary user can edit."}