{"version":"2.1.281","anchor":"trust-check-no-more-blanket-bypass-ancestor-trust-returns","canonical_anchor":"trust-check-no-more-blanket-bypass-ancestor-trust-returns","heading":"Workspace trust check reworked: reports which folder is trusted and drops a blanket bypass","tier":"notice","area":"Workspace Trust","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/trust-check-no-more-blanket-bypass-ancestor-trust-returns","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Workspace trust check reworked: reports which folder is trusted and drops a blanket bypass\n\nThe folder trust check now returns which parent folder's trust applies, drops an unconditional bypass, and always returns true or false\n\n**Unclear.** The finding does not say under what condition the removed shortcut applied.\n\n**What**\n\nClaude Code asks you to trust a folder before working in it, and it remembers when you accepted (`hasTrustDialogAccepted`). The check that looks this up changed:\n\n- The walk up through parent folders now returns the path of the trusted folder, or nothing, instead of just yes or no. A new helper tells callers which project path is trusted.\n\n- An early step that trusted the workspace unconditionally in some cases has been removed.\n\n- The workspace-trust check `CI` now uses this helper and turns its answer into a true or false result. In the advisory branch that does not touch the file system, it now returns a proper true or false where it may have returned another value before.\n\n**Why**\n\nMost of this is internal. Because the unconditional bypass is gone, some kinds of session that were trusted automatically may now need real folder trust. Claude Code can also now say which parent folder's trust is being applied.\n\n- Area: Workspace Trust\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}