{"version":"2.1.284","anchor":"projects-sessions-lock-down-webfetchwebsearch-permissions","canonical_anchor":"projects-sessions-lock-down-webfetchwebsearch-permissions","heading":"Projects sessions keep WebFetch and WebSearch approvals to the current session","tier":"notice","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/projects-sessions-lock-down-webfetchwebsearch-permissions","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Projects sessions keep WebFetch and WebSearch approvals to the current session\n\nIn Projects sessions, 'always allow' for WebFetch or WebSearch is saved for the session only, and hooks and plugins can no longer grant these tools\n\n**Unclear.** Apart from the environment variable, how Claude Code decides a session is a Projects session is not stated.\n\n**What**\n\nWebFetch and WebSearch are the tools Claude uses to read web pages and search the web. In certain sessions, permission to use them can no longer be saved permanently or granted by add-ons.\n\n- When it applies: `CLAUDE_CODE_PROJECTS_SESSION` is set, or the `hearthbot` MCP tool has been called with a URL that passes a check, or a further check the findings did not identify passes.\n\n- Saved choices: every place that saves your permission choice (the host dialog, the permission prompt, `PermissionRequest` hook allows and the network-permission launcher) now drops allow rules for WebFetch and WebSearch. The rule for the request in hand (WebSearch itself, or WebFetch `domain:<host>`) is kept but saved for the current session only. Rules from the `session` and `cliArg` sources are exempt.\n\n- Remove and replace updates for these tools are rewritten so stored deny and ask rules are kept.\n\n- Hooks: a `PermissionRequest` hook that allows a call has any updates that would loosen WebFetch or WebSearch rules stripped, and its allow for these tools is ignored. The existing rule that a confined session only takes grants from its command line is kept.\n\n- Plugins: a plugin's `tool.check` hook can only tighten these tools, not allow them (\"plugins can only tighten ... permission in a Projects session\").\n\n- The protection is lifted only when the server payload carries `bot_protected_tengu_atomic_magpie` as true, plus a further condition that was not read. Nothing has been read about the `tengu_atomic_magpie` gate.\n\n**Why**\n\nIn these sessions, choosing \"always allow\" for a web fetch or search no longer lasts past the session, and hooks or plugins cannot quietly open these tools up. Expect to be asked again in each new session.\n\n- Area: Permissions\n- Names: `CLAUDE_CODE_PROJECTS_SESSION`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 3\/5"}