From 0883101b178c46a3a029a3b33265f49b89d4894b Mon Sep 17 00:00:00 2001 From: Jeroen Schweitzer Date: Sun, 9 Aug 2026 13:42:04 +0200 Subject: [PATCH] chore(claude): deny toj in the sub-repos toj is now on the global PATH as /usr/local/bin/toj, so its scope boundary had to stop being "the absolute path is inconvenient to type" and start being a rule. Its repo and settings verbs operate on the workspace root; run from inside this repo they answer about the wrong tree. Both spellings are denied, bare and absolute, because a deny with one spelling left open is decorative. Co-Authored-By: Claude --- .claude/settings.json | 74 +++++++++++++++++++++++-------------------- 1 file changed, 39 insertions(+), 35 deletions(-) diff --git a/.claude/settings.json b/.claude/settings.json index a3afdbb..a0a33fc 100644 --- a/.claude/settings.json +++ b/.claude/settings.json @@ -18,43 +18,47 @@ "Bash(curl -s http://localhost:8095/*)" ], "deny": [ - "Bash(sudo *)", - "Bash(su *)", + "Bash(/mnt/media/Projects/cladmin/ops/bin/toj)", + "Bash(/mnt/media/Projects/cladmin/ops/bin/toj:*)", + "Bash(chmod -R 777 *)", + "Bash(chmod 777 *)", + "Bash(dd if=*)", + "Bash(find * -delete*)", + "Bash(find * -exec*)", + "Bash(git * add --all*)", + "Bash(git * add -A*)", + "Bash(git * add .)", + "Bash(git * branch -D *)", + "Bash(git * checkout -- *)", + "Bash(git * clean -fd*)", + "Bash(git * clean -fdx*)", + "Bash(git * commit --no-verify*)", + "Bash(git * merge --no-ff*)", + "Bash(git * push --force*)", + "Bash(git * push -f*)", + "Bash(git * reset --hard*)", + "Bash(git * restore .*)", + "Bash(git add --all*)", + "Bash(git add -A*)", + "Bash(git add .)", + "Bash(git branch -D *)", + "Bash(git checkout -- *)", + "Bash(git clean -fd*)", + "Bash(git clean -fdx*)", + "Bash(git commit --no-verify*)", + "Bash(git merge --no-ff*)", + "Bash(git push --force*)", + "Bash(git push -f*)", + "Bash(git reset --hard*)", + "Bash(git restore .*)", + "Bash(mkfs*)", + "Bash(rm -rf $HOME*)", "Bash(rm -rf /*)", "Bash(rm -rf ~*)", - "Bash(rm -rf $HOME*)", - "Bash(mkfs*)", - "Bash(dd if=*)", - "Bash(chmod 777 *)", - "Bash(chmod -R 777 *)", - "Bash(find * -exec*)", - "Bash(find * -delete*)", - "Bash(git add -A*)", - "Bash(git * add -A*)", - "Bash(git add --all*)", - "Bash(git * add --all*)", - "Bash(git add .)", - "Bash(git * add .)", - "Bash(git push --force*)", - "Bash(git * push --force*)", - "Bash(git push -f*)", - "Bash(git * push -f*)", - "Bash(git reset --hard*)", - "Bash(git * reset --hard*)", - "Bash(git clean -fd*)", - "Bash(git * clean -fd*)", - "Bash(git clean -fdx*)", - "Bash(git * clean -fdx*)", - "Bash(git branch -D *)", - "Bash(git * branch -D *)", - "Bash(git checkout -- *)", - "Bash(git * checkout -- *)", - "Bash(git restore .*)", - "Bash(git * restore .*)", - "Bash(git commit --no-verify*)", - "Bash(git * commit --no-verify*)", - "Bash(git merge --no-ff*)", - "Bash(git * merge --no-ff*)" + "Bash(su *)", + "Bash(sudo *)", + "Bash(toj)", + "Bash(toj:*)" ] } }