Skip to content

chore(claude): lift home-directory sandbox restriction in local settings - #440

Merged
codewizdave merged 1 commit into
mainfrom
t3code/expliquer-le-projet-1
Aug 20, 2026
Merged

codewizdave merged 1 commit into
mainfrom
t3code/expliquer-le-projet-1

Conversation

@martyy-code

Copy link
Copy Markdown
Contributor

Summary

Drop the deny rules that blocked Read/Write/Edit on ~/** in .claude/settings.local.json, along with the negation overrides (!Read(./**), etc.) that re-allowed the project tree on top of them. The remaining allow list already covers everything we need:

  • Read(*), Write(*), Edit(*), Bash(*) for unrestricted workspace access.
  • Read(//tmp/**) for temp-file reads.
  • The deny list keeps the dangerous operations blocked: kill/pkill, rm -rf / , sudo, chmod, git rebase, git reset --hard, git clean, etc.

The removed layer was redundant: once Read(*) is allowed, denying Read(~/**) and re-allowing !Read(./**) cancels out and adds noise without any actual restriction.

Files changed

  • .claude/settings.local.json — 7 lines removed.

Impact

Local-only. .claude/settings.local.json is per-developer configuration and is not consumed by CI, builds, or the published @deessejs/fp package. No runtime, type, test, or documentation changes.

Checklist

  • pnpm --filter @deessejs/fp test:run — N/A (config-only change)
  • pnpm --filter @deessejs/fp lint — N/A (config-only change)
  • No changeset needed — not a user-facing API change

Remove the deny rules that blocked Read/Write/Edit on ~/**, along with the
negation overrides that re-allowed the project tree. The remaining allow
list (Read(*), Write(*), Edit(*), Bash(*)) already covers the workspace
paths, so the extra layer is redundant.

No impact on production — settings.local.json is per-developer and
gitignored on a normal install.
@github-actions

Copy link
Copy Markdown
Contributor

Coverage report

File % Stmts % Branch % Funcs % Lines
Total 100.00% 100.00% 100.00% 100.00%
packages/fp/src/function/compose.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/function/const-thunks.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/function/constant.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/function/endomorphism.ts 0.00% n/a 0.00% 0.00%
packages/fp/src/function/flip.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/function/flow.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/function/function-n.ts 0.00% n/a 0.00% 0.00%
packages/fp/src/function/identity.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/function/index.ts 0.00% n/a 0.00% 0.00%
packages/fp/src/function/lazy.ts 0.00% n/a 0.00% 0.00%
packages/fp/src/function/pipe.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/function/predicate.ts 100.00% 100.00% 100.00% 100.00%
packages/fp/src/function/tuple.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/function/tupled.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/function/untupled.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/maybe/constants.ts 100.00% 100.00% 100.00% 100.00%
packages/fp/src/maybe/functions.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/maybe/index.ts 0.00% n/a 0.00% 0.00%
packages/fp/src/maybe/internal/none-impl.ts 100.00% 100.00% 100.00% 100.00%
packages/fp/src/maybe/internal/some-impl.ts 100.00% 100.00% 100.00% 100.00%
packages/fp/src/result/attempt.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/result/classify.ts 100.00% 100.00% 100.00% 100.00%
packages/fp/src/result/constants.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/result/functions.ts 100.00% n/a 100.00% 100.00%
packages/fp/src/result/index.ts 0.00% n/a 0.00% 0.00%
packages/fp/src/result/internal/attempt-impl.ts 100.00% 100.00% 100.00% 100.00%
packages/fp/src/result/internal/err-impl.ts 100.00% 100.00% 100.00% 100.00%
packages/fp/src/result/internal/ok-impl.ts 100.00% 100.00% 100.00% 100.00%
packages/fp/src/result/reporting.ts 100.00% 100.00% 100.00% 100.00%
packages/fp/src/result/wrapping.ts 100.00% 100.00% 100.00% 100.00%
packages/fp/src/unit/constants.ts 100.00% 100.00% 100.00% 100.00%
packages/fp/src/unit/index.ts 0.00% n/a 0.00% 0.00%

Per-file thresholds: 100% on statements / branches / functions / lines (ADR 0002). Files with no branches render n/a in the Branch column. The threshold gate is disabled in this PR and lands with the full method × variant test matrix in a follow-up.

@codewizdave
codewizdave merged commit 4c86fd3 into main Aug 20, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants