{"version":"2.1.286","anchor":"url-allowlist-match-now-exact-for-non-slash-entries","canonical_anchor":"url-allowlist-match-now-exact-for-non-slash-entries","heading":"URL allowlist entries without a trailing slash now match only exact paths","tier":"notice","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/url-allowlist-match-now-exact-for-non-slash-entries","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### URL allowlist entries without a trailing slash now match only exact paths\n\nA URL path allowlist now treats only entries ending in `\/` as prefixes; any other entry must match the path exactly\n\n**Unclear.** It is unclear which allowlist in Claude Code this check belongs to.\n\n**What**\n\nClaude Code checks some URLs against an allowlist of paths. Before, every entry matched any path that began with it. Now:\n\n- An entry ending in `\/` still matches every path that starts with it.\n\n- Any other entry matches only that exact path.\n\n**Why**\n\nURL matching is stricter. For example, an entry `\/docs` no longer also allows `\/docs-private`.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}