{"version":"2.1.283","anchor":"invalid-sandbox-settings-now-validated-per-field-keeping-re","canonical_anchor":"invalid-sandbox-settings-now-validated-per-field-keeping-re","heading":"A bad sandbox setting no longer switches off the whole sandbox block","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/invalid-sandbox-settings-now-validated-per-field-keeping-re","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### A bad sandbox setting no longer switches off the whole sandbox block\n\nInvalid sandbox settings are now handled one field at a time, falling back to the restrictive value instead of the whole block being ignored\n\n**Unclear.** Which sandbox fields have a restrictive fallback value is not listed.\n\n**What**\n\nThe sandbox is the protection that limits which files and network addresses Claude Code's commands can reach. Before, if anything in the `sandbox` settings failed validation, the whole block was ignored with \"This field was ignored.\", and only the credentials part was rescued.\n\nNow each field is checked on its own:\n\n- Invalid fields: each one falls back to its restrictive value, or is ignored by itself.\n\n- `sandbox.failIfUnavailable`: never filled in with a substitute value.\n\n- `sandbox.enabled`: not filled in with a restrictive value when invalid.\n\n- Warnings: when an invalid field has a restrictive value that was not used, the warning names that value.\n\n- Credentials: damaged credential entries are now marked as substituted.\n\n- Text values: \"true\" and \"false\" written as text, and `false` meaning \"disable\", are handled the same way everywhere.\n\n**Why**\n\nOne typo in a sandbox setting no longer turns off every other sandbox protection.\n\n- Area: Sandbox\n- Names: `sandbox.enabled`\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 1\/5"}