{"version":"2.1.282","anchor":"permission-answers-from-a-host-owned-dialog-are-only-trusted","canonical_anchor":"permission-answers-from-a-host-owned-dialog-are-only-trusted","heading":"Permission answers from a host's own dialog are trusted only for prompts it was sent","tier":"notice","area":"SDK","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282\/e\/permission-answers-from-a-host-owned-dialog-are-only-trusted","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282","markdown":"### Permission answers from a host's own dialog are trusted only for prompts it was sent\n\nWhen a host app shows permission prompts, Claude Code only accepts its approval for a request it actually sent to that host, and uses it once\n\n**Unclear.** It is not clear whether the previous build already let each answer count only once.\n\n**What**\n\nSome programs embed Claude Code and show its permission prompts in their own dialog. A permission prompt is the question Claude Code asks before it runs a tool, such as editing a file or running a command. In that setup, Claude Code now keeps its own record of which `can_use_tool` requests it actually sent to the host's dialog.\n\n- A request is recorded when Claude Code sends it to the host's permission prompt.\n\n- A successful answer counts as answered in the host's dialog only if Claude Code recorded that request first.\n\n- Once Claude Code has used that record, it is cleared, so a single answer counts one time only.\n\nPreviously, any matching answer was recorded as answered in the host's dialog, with no check that the request had gone through the host's prompt.\n\n**Why**\n\nA stray or forged answer can no longer mark a tool approval as given by a person in the host's dialog when that dialog never showed the request.\n\n- Area: SDK\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}