Skip to content

Deny Read/Grep access to secret-shaped files - #3

Merged
lorenzoliuzzo merged 2 commits into
mainfrom
chore/claude-secret-deny-patterns
Jul 8, 2026
Merged

Deny Read/Grep access to secret-shaped files#3
lorenzoliuzzo merged 2 commits into
mainfrom
chore/claude-secret-deny-patterns

Conversation

@lorenzoliuzzo

Copy link
Copy Markdown
Contributor

Adds a .claude/settings.json with the same permissions.deny block used in the fleet-dispatch workspace root, so sessions opened directly in this repo (not just at the MyThingsLab workspace root) block Read/Grep on .env*, *.pem, *.key, *credentials*, *secret*, id_rsa, id_ed25519.

Part of a fleet-wide backfill closing a gap found while testing the deny patterns: repo-scoped Claude Code sessions didn't inherit the parent workspace's protection.

lorenzoliuzzo and others added 2 commits July 8, 2026 19:52
Adds the same permissions.deny block already in the fleet-dispatch
workspace root, so a session opened directly in this repo also blocks
Read/Grep on .env*, *.pem, *.key, *credentials*, *secret*, id_rsa,
id_ed25519 -- previously only sessions started at the MyThingsLab
workspace root inherited this protection.
@lorenzoliuzzo
lorenzoliuzzo merged commit 0ea28c6 into main Jul 8, 2026
1 check passed
@lorenzoliuzzo
lorenzoliuzzo deleted the chore/claude-secret-deny-patterns branch July 12, 2026 12:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant