Skip to content

fix(claude): allow reading and editing .env*.example files - #640

Merged
p-chan merged 2 commits into
mainfrom
fix-env-example-permission
Sep 23, 2026
Merged

p-chan merged 2 commits into
mainfrom
fix-env-example-permission

Conversation

@p-chan

@p-chan p-chan commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Why

The deny rules Read(!.env*.example) and Edit(!.env*.example) were meant to exempt example files from Read(.env*) and Edit(.env*), but permission rules have no negation. Each rule is matched independently, so .env.example was denied as well.

What

  • Add home/.claude/hooks/personal-block-env.sh, a PreToolUse hook that denies .env* files except .env*.example
    • Match file names case-insensitively for case-insensitive file systems
    • Block the tool call with exit code 2 when the check fails
  • Run the hook for Read, Edit, Write, MultiEdit, and NotebookEdit
  • Replace the .env* deny rules in home/.claude/settings.json with Read deny rules for common names (.env, .env.local, .env.*.local, .env.development, .env.production), because @ mentions do not trigger PreToolUse hooks

Notes

  • Unlike Read deny rules, the hook does not cover the Grep and Glob tools. This will be handled separately
  • The hook checks the given file name and does not resolve symlinks

Deny rules have no negation, so `.env*` also blocked `.env*.example`.
Move the check to a PreToolUse hook that exempts example files.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@p-chan p-chan self-assigned this Sep 23, 2026
- Match file names case-insensitively for case-insensitive file systems
- Block the tool call when the check fails instead of allowing it
- Keep Read deny rules for common .env names, because @ mentions do
  not trigger PreToolUse hooks

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@p-chan
p-chan merged commit eaaf9b0 into main Sep 23, 2026
6 checks passed
@p-chan
p-chan deleted the fix-env-example-permission branch September 23, 2026 20:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant