{"version":"2.1.288","anchor":"cloud-sessions-seed-user-settings-with-a-restrict-only-merge","canonical_anchor":"cloud-session-served-settings-new-warnings-and-claude-appl","heading":"Cloud sessions served by your computer take settings more cautiously","tier":"use","area":"Cloud Sessions","scope":"both","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/cloud-sessions-seed-user-settings-with-a-restrict-only-merge","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Cloud sessions served by your computer take settings more cautiously\n\nWhen your computer serves a cloud session, changed project settings are held back until `claude apply-project-settings`, and user settings can only tighten\n\n**Unclear.** What the switch falls back to when the server sends nothing is not known.\n\n**What**\n\nA computer can serve a cloud session, meaning a session started in the cloud runs its commands on that machine. How settings apply in that situation changed.\n\n- Project settings files are recorded when the session attaches, and later changes to them are held back. They apply only after you run `claude apply-project-settings` in a terminal in that folder to review them. The settings are applied again when the session ends.\n\n- Three new messages cover held-back settings, settings taken as found, and folder hooks and plugin settings not being used. The old message saying a change applies to the session now using this computer was removed.\n\n- Command text now says that commands start in the project folder and that a `cd` carries over.\n\n- Behind `tengu_quiet_locket`, your user settings are recorded at attach and merged in a way that can only restrict. Deny and ask rules and sandbox deny lists are added, while an allow rule is kept only if both sides have it. Restrictions that come from your settings, such as `read_block` or `auto_mode_off`, are recorded. If the recorded settings cannot be read, the session stops with an error telling you to run `claude apply-project-settings`. The flag server returned on for this site's account and for the anonymous baseline, but no reading has been taken under this release yet.\n\n- The MCP policy decided at attach now also receives those user settings (`userSettingsAtAttach`). MCP servers are add-ons that give Claude extra tools.\n\n**Why**\n\nA cloud session can no longer change project settings and have them take effect on your own machine without your review. Your local permission rules can tighten what the session may do but cannot loosen it.\n\n- Flag `tengu_quiet_locket`: Gate removed from the code (read for one account on one subscription tier against v2.1.288; this account: on, anonymous baseline: on, compiled default: not a boolean we can read) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Cloud Sessions\n- Tier: Use it now\n- Useful: 5\/5\n- Signal: 3\/5\n- Scope: both\n- Heads-up: yes"}