Claude Code v2.1.286 ·
URL allowlist entries without a trailing slash now match only exact paths
A URL path allowlist now treats only entries ending in / as prefixes; any other entry must match the path exactly
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.286,
ImprovementsSection of the release
What
Claude Code checks some URLs against an allowlist of paths. Before, every entry matched any path that began with it. Now:
- An entry ending in
/ still matches every path that starts with it.
- Any other entry matches only that exact path.
Why
URL matching is stricter. For example, an entry /docs no longer also allows /docs-private.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is unclear which allowlist in Claude Code this check belongs to.
See this entry in the whole of v2.1.286 →