{"version":"2.1.290","anchor":"stage-file-and-home-seed-hardening","canonical_anchor":"stage-file-and-home-seed-hardening","heading":"Cloud session file staging refuses backslashes and paths that leave its folder","tier":"notice","area":"Cloud Sessions","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/stage-file-and-home-seed-hardening","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Cloud session file staging refuses backslashes and paths that leave its folder\n\nWhen placing a file for a cloud session, Claude Code now rejects folder names with backslashes and destinations outside the staging folder\n\n**Unclear.** It is not clear when these checks run or what the settings helper is used for.\n\n**What**\n\nWhen Claude Code stages a file, meaning it places the file into a holding folder before use, it now checks the destination more strictly:\n\n- A folder on the way to the destination whose name contains a backslash is rejected.\n\n- A destination whose parent folder sits outside the staging folder is rejected.\n\nSeparately, a helper that prepares a settings document for the home folder now merges the deny and ask permission rules into it. Deny rules block an action, and ask rules make Claude Code ask you first.\n\n**Why**\n\nThese checks apply to cloud sessions only, and they stop a staged file from landing somewhere other than the folder it was meant for.\n\n- Area: Cloud Sessions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}