Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.290 ·

Wildcard URL rules handle international domain names more safely

Wildcard web address rules now protect punycode host names, and a rule with the wildcard inside part of a host name is refused

You'll notice Improvements
JSON All of v2.1.290
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release

Unclear It is not clear whether every rule with a wildcard inside a host name part is refused, or only ones involving punycode.

What

Permission rules can allow or block web addresses using a wildcard, a placeholder that matches anything. Matching has changed:

  • Host name parts written in punycode are protected during matching. Punycode is how domain names with non-English letters are stored, as text starting with xn--.
  • A rule whose wildcard sits inside a single part of a host name is refused and matches nothing.
Why

This tightens domain allow and deny rules so a wildcard cannot slip into a lookalike or international domain name it was not meant to cover.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear whether every rule with a wildcard inside a host name part is refused, or only ones involving punycode.
Anthropic's release notes agreeFixed URL allow and deny patterns with a wildcard inside an xn-- host label matching differently from one process to the next

See this entry in the whole of v2.1.290 →

Feedback