{"version":"2.1.289","anchor":"read-deny-check-refactored-attachment-reads-use-it","canonical_anchor":"read-deny-check-refactored-attachment-reads-use-it","heading":"Read-deny check for attached files now goes through shared helpers","tier":"internal","area":"Permissions","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.289\/e\/read-deny-check-refactored-attachment-reads-use-it","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.289","markdown":"### Read-deny check for attached files now goes through shared helpers\n\nChecking whether a deny rule blocks reading an attached file now uses a shared helper that also tests whether any read-deny rules exist\n\n**Unclear.** It is not clear whether attachments are blocked any differently than before.\n\n**What**\n\nDeny rules are permission settings that stop Claude Code from reading certain files. The check that applies them to reads has been split into two helpers. One tests whether a rule blocks a read. The other does the same and also tests whether any read-deny rules exist at all, reusing a ready-made list of rules when one is available. Files attached to a prompt are now checked through this second helper.\n\n**Why**\n\nThis may change which attached files are blocked by deny rules. The old and new checks look very similar, so the visible effect may be small or none.\n\n- Area: Permissions\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 0\/5\n- Scope: individual\n- Heads-up: no"}