{"version":"2.1.290","anchor":"wsl-and-credential-path-protections-sandbox-read-config","canonical_anchor":"wsl-and-credential-path-protections-sandbox-read-config","heading":"More credential files blocked on WSL and Windows","tier":"notice","area":"Permissions","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/wsl-and-credential-path-protections-sandbox-read-config","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### More credential files blocked on WSL and Windows\n\nClaude Code now also protects Windows profile credential files reached through WSL's \/mnt paths and through Windows short file names\n\n**Unclear.** Which part of this the `tengu_ticklish_pnueli` flag controls is not clear.\n\n**What**\n\nClaude Code keeps a list of sensitive credential files that it blocks access to. That list now covers more locations:\n\n- Windows profile credential files reached from WSL (Windows Subsystem for Linux) through `\/mnt` paths.\n\n- The same files reached through Windows short file names, the old 8.3-style names such as `PROGRA~1`.\n\nThe sandbox, which limits what commands Claude runs can touch, now also handles read rules that point outside the project folder and rules it cannot decide either way. This build also reads a server flag, `tengu_ticklish_pnueli`, which is off unless it is switched on remotely. The flag server has returned it on for this site's account.\n\n**Why**\n\nOn WSL and Windows the same credential file can be reached under more than one path. Blocking those extra paths makes it harder to read the file by going around the usual name.\n\n- Flag `tengu_ticklish_pnueli`: Off by default, switched on for this account (read for one account on one subscription tier against v2.1.290; this account: on, anonymous baseline: on, compiled default: off) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: yes"}