Unclear It is not clear whether the new deny-rule check sits behind the same remote switch as the approval retry.
What
Some tools reach Claude Code through claude.ai, which passes the calls along (a proxy). That proxy can answer with error -32003 needs_approval, meaning the call needs your approval first. Until now Claude Code always showed an approval card after the fact in that case.
Now Claude Code first checks the site against your ClaudeInChromeDomain deny rules, which are rules that block Claude in Chrome from certain websites.
- If a deny rule covers the site, the call fails and no approval card is shown. The error code is
ccr_proxy_needs_approval_chrome_site_denied. - If the site cannot be read and any deny rules exist, the call also fails with no card.
- Otherwise the approval card appears as before, and it can now be a card for that specific site.
The retry is still controlled by the remote switch tengu_mcp_proxy_needs_approval_retry, which falls back to on in the code when the server sends no value. No reading of that switch has been taken.
Why
Domain deny rules you set for Chrome now also apply when a call comes through a claude.ai connector, instead of being worked around by an approval prompt you could click through.
tengu_mcp_proxy_needs_approval_retry Not enough to sayNothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.
This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.295: on
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.295. It isn't a statement about your account. What a flag value here can and cannot tell you
It is not clear whether the new deny-rule check sits behind the same remote switch as the approval retry.