{"version":"2.1.288","anchor":"sandbox-read-rule-collection-now-includes-user-settings-pass","canonical_anchor":"sandbox-read-rule-collection-now-includes-user-settings-pass","heading":"Sandbox file-read rules gather more sources","tier":"internal","area":"Elsewhere","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/sandbox-read-rule-collection-now-includes-user-settings-pass","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Sandbox file-read rules gather more sources\n\nThe sandbox's file-read rules now include user settings passed in directly, allowRead re-opens and credential files resolved across all settings levels\n\n**Unclear.** What part of Claude Code passes these settings in is not known.\n\n**What**\n\nThe sandbox limits which files commands run by Claude Code can touch. Part of its setup is a list of files it may not read, plus exceptions that open some of them again. This release changes how that list is put together.\n\n- The function that collects read rules now accepts an optional settings object. It merges deny and ask rules from user settings, plus sandbox re-opens, from that object and removes duplicates. Before, rules came only from settings already loaded from their usual places.\n\n- Sandbox `allowRead` entries, called re-opens because they open up paths that were otherwise blocked, are now collected as well.\n\n- Sandbox credential files (`credentials?.files`) are now worked out once across every settings level up front, instead of inside the loop over each level. Their deny forms feed the check that decides whether an `allowRead` entry re-opens a path.\n\n**Why**\n\nUser-settings edits that have not been saved yet are now taken into account when deciding which files the sandbox blocks. Credential files are checked against `allowRead` re-opens, which affects whether an exception can open them up.\n\n- Area: Elsewhere\n- Names: `allowRead`\n- Tier: Under the hood\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: no"}