{"version":"2.1.290","anchor":"mcp-session-wide-permission-and-read-deny-checks-on-editwri","canonical_anchor":"mcp-session-wide-permission-and-read-deny-checks-on-editwri","heading":"Remote tool calls now obey the session's read-deny rules","tier":"notice","area":"Permissions","scope":"both","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/mcp-session-wide-permission-and-read-deny-checks-on-editwri","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Remote tool calls now obey the session's read-deny rules\n\nTool calls served to a remote session are now refused when a read-deny rule matches the path, or when the rules cannot be checked\n\n**Unclear.** Exactly which tools these checks cover is not clear.\n\n**What**\n\nPermission rules decide what Claude may do. A deny rule blocks an action outright, and an ask rule makes Claude ask you first. When a computer offers its tools to a session, Claude Code checks each incoming call against that session's rules. Before, it checked only general deny rules. It now also:\n\n- refuses a call with `denied_by_session_read_deny` when a rule blocking reads of a path matches\n\n- refuses a call when its rules cannot be checked at all\n\n- applies ask rules to paths that a tool reads\n\n**Why**\n\nTools offered to a session could get around rules that block reading certain files. Those rules now hold for remote calls too.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: both\n- Heads-up: yes"}