{"version":"2.1.290","anchor":"proxyauthhelper-person-and-policy-sources-run-in-the-user-d","canonical_anchor":"proxyauthhelper-person-and-policy-sources-run-in-the-user-d","heading":"Proxy auth helper runs under new rules for personal and policy sources","tier":"use","area":"Network Proxy","scope":"both","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/proxyauthhelper-person-and-policy-sources-run-in-the-user-d","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Proxy auth helper runs under new rules for personal and policy sources\n\nWith sources set to personAndPolicy, the proxy auth helper is skipped under folder trust or else runs from another folder\n\n**Unclear.** What sets the sources value, and which folder the helper now runs from, are not settled.\n\n**What**\n\nThe proxy auth helper is a script Claude Code runs to get credentials for a network proxy. When `proxyAuthHelperConfig.sources` is set to `personAndPolicy`:\n\n- The helper is skipped where the folder's trust check applies.\n\n- Otherwise it runs from a different working folder than before.\n\nBefore, the only check was the project and local trust check. The helper still receives `CLAUDE_CODE_PROXY_URL`, `CLAUDE_CODE_PROXY_HOST` and `CLAUDE_CODE_PROXY_AUTHENTICATE`.\n\n**Why**\n\nThis changes when a script that handles credentials is allowed to run, which matters for security.\n\n- Area: Network Proxy\n- Names: `proxyAuthHelperConfig.sources`\n- Tier: Use it now\n- Useful: 3\/5\n- Signal: 2\/5\n- Scope: both\n- Heads-up: yes"}