{"version":"2.1.288","anchor":"served-remote-tool-sessions-refuse-edits-to-settings-files","canonical_anchor":"served-remote-tool-sessions-refuse-edits-to-settings-files","heading":"Network paths always need approval, and served sessions refuse to edit settings files","tier":"notice","area":"Sessions","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/served-remote-tool-sessions-refuse-edits-to-settings-files","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Network paths always need approval, and served sessions refuse to edit settings files\n\nFiles on network paths are no longer auto-approved, and served sessions refuse edits to settings files, with clearer reasons in the prompt\n\n**Unclear.** It is not clear when a session counts as served or exactly what you see when an edit is refused.\n\n**What**\n\nClaude Code's permission checks decide what Claude may do on its own and what needs your approval. They get stricter in two places:\n\n- Network paths: a file on a network location (UNC paths such as `\\\\server\\share`, automounted folders, or paths outside trusted network directories) is now flagged as a network path. It is never approved automatically, and the prompt gives the new reason `network_path`.\n\n- Served sessions: when a session runs tools on this computer for a remote session, any tool that would edit or write a settings file is refused.\n\n- Ask prompts in served sessions now open with `ask.outside_sandbox` and `ask.settings_person_only` text, and your own settings now take part in those permission checks.\n\n- New messages explain why a person must approve, for example \"This can delete files or discard changes for good, so a person needs to approve it.\" These are chosen by the gate `tengu_reactive_zephyr`, which has not been read, so whether they appear for any given account is unknown.\n\n**Why**\n\nNetwork paths and settings files are places where an automatic action could reach further than expected or change how Claude Code itself behaves. These changes put a person back in the loop for them.\n\n- Flag `tengu_violin_purfling`: On for this account, and not off by default (read for one account on one subscription tier against v2.1.288; this account: on, anonymous baseline: on, compiled default: not a boolean we can read) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Flag `tengu_reactive_zephyr`: Off in both readings (read for one account on one subscription tier against v2.1.288; this account: off, anonymous baseline: off, compiled default: not a boolean we can read) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Sessions\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: yes"}