{"version":"2.1.285","anchor":"sandbox-network-strictallowlist-admin-mandate-ignores-proj","canonical_anchor":"sandbox-network-strictallowlist-admin-mandate-ignores-proj","heading":"Strict sandbox network allowlist now ignores domains allowed by a project","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/sandbox-network-strictallowlist-admin-mandate-ignores-proj","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Strict sandbox network allowlist now ignores domains allowed by a project\n\nUnder `sandbox.network.strictAllowlist` or an admin mandate, websites allowed in project or local settings are no longer added\n\n**Unclear.** It is not clear what switches on the administrator sandbox requirement.\n\n**What**\n\nThe sandbox limits which websites commands run by Claude can reach. When `sandbox.network.strictAllowlist` is on, or an administrator requires the sandbox, Claude Code now ignores websites allowed in project settings and local settings. Before, those were added to the list. This covers:\n\n- `sandbox.network.allowedDomains`\n\n- `WebFetch(domain:)` permission rules\n\nA debug log notes how many entries were ignored.\n\n**Why**\n\nA repository you clone can no longer widen which websites the sandbox allows through its own settings files. Websites you need must be allowed in user or managed settings instead.\n\n- Area: Sandbox\n- Names: `sandbox.network.strictAllowlist`\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 1\/5"}