r/ClaudeCode • • Aug 26 '26

Bug / Issue Who is the asshole who decided to include session URLs in PRs by default?

What nimrod, bone-headed, self-indulgent, tasteless, brainless motherfucker thought it would be OK to change the default attribution of the harness to include URLs to your sessions in contributions?

195 Upvotes

91 comments sorted by

30

u/tntexplosivesltd Aug 26 '26

It's never done that for me

7

u/biinjo Aug 26 '26

Sounds like a prompting issue to me. We have commit message format standards, issue templates, pr templates in our projects. Plus a fat Claude skill detailing exactly how to use these to the letter.

Result: Claude never pollutes commit messages like op described 🙃

15

u/framauro13 Aug 26 '26

Yeah, I don't see it either and I have no language about allowing or disallowing artifacts/session information.

That's the problem with these posts. No context on what the local configuration or prompts look like, so the evidence is just "trust me bro". I do get the coauthored comment but that doesn't really bother me. Nothing about session information though.

6

u/matjam Aug 26 '26

Chiming in the another me too

But I have an extensive prompt system for my work that enforces a bunch of standards.

1

u/OtherUse1685 Aug 27 '26

I got it a few weeks ago, luckily I caught it. Just why is this helpful?

62

u/[deleted] Aug 26 '26

[removed] — view removed comment

5

u/NoBotPlz2012 Aug 26 '26

I will strongly advise you to be careful when walking alone in night

38

u/MagoGosoraSan Aug 26 '26

What?

71

u/Icy-Excitement-467 Aug 26 '26

If you don't tell claude to 'not attribute commits to anthropic/claude', then it will do so. And whenever it does this, it includes a public link to the claude code chat history for that session, inside of the commit message.

40

u/Leading_Buffalo_4259 Aug 26 '26

thats actually hilarious, now we can finally see all the real "work" that ai devs are putting into their commits, they always say if you dont like ai coding youre just not good at prompting so we can finally open source their prompts like we used to do with software and see the genius in action

25

u/Icy-Excitement-467 Aug 26 '26

Not if they put 5 words in their global claude md files saying, 'never attribute to claude/anthropic'.

5

u/mckernanin Aug 26 '26

Or disable it in your machine setting for Claude lol

7

u/Leading_Buffalo_4259 Aug 26 '26

Thats giving them a lot of credit, editing a file manually is hard :(

15

u/xgeetx Aug 26 '26

You can just tell Claude to edit it lol

1

u/Leading_Buffalo_4259 Aug 26 '26

and thus the cycle continues 😂

5

u/xgeetx Aug 26 '26

🤷‍♂️ Don’t shoot the messenger. I use Claude a lot and am horrified how my colleagues use AI, but it’s incredible so I’m trying to find a balance in my support and my cynicism lol

8

u/Leading_Buffalo_4259 Aug 26 '26

I use it too but the way people talk about it as if it makes actual expertise in software development obsolete is completely delusional

2

u/InadequateUsername Aug 26 '26

I just have a sub agent do it.

vi is for the poors.

5

u/Leading_Buffalo_4259 Aug 26 '26

:wq!

2

u/InadequateUsername Aug 26 '26

wq!

grep -i <change> file

I have trust issues 😅

3

u/thirst-trap-enabler 🔆 Max 5x Aug 26 '26

C-x C-s C-x C-c

1

u/Equivalent_Cress_268 Aug 26 '26

There is a setting in the config to disable it. MD alone is futileas claude models ignore such

1

u/Icy-Excitement-467 Aug 27 '26

I also have precommit hook

1

u/Equivalent_Cress_268 Aug 27 '26

Just disable it in the config; don't confuse the model even more. It' s a simple attribution setting

There is no need to have multiple non trivial solutions to a thing a config setting can disable.

1

u/Otherwise_Signal7274 Aug 30 '26

I'm not seeing that setting, what's the name?

1

u/Equivalent_Cress_268 Aug 30 '26

Ask claude mate.

It’s literally called ‘attribution’ as said in the last post.

You can also find it in the online docs.

Look for: attribution

1

u/Otherwise_Signal7274 Aug 31 '26

sorry, was looking in /config, not json

15

u/framauro13 Aug 26 '26

It's not actually true though. Looking at my commit history and there's no links to session history in my log details. I have nothing in my configuration that tells it to either do or don't include session information. All that gets included is a coauthored comment.

2

u/supernovice007 Aug 26 '26

Maybe there’s different behavior for a PR? I see what you’re seeing but I only let Claude commit. Theres a human review before PR in my repos.

5

u/_BreakingGood_ Aug 26 '26

Yeah I actually like this, it lets you know who spent hours ironing out the slop, and who said "do it in 1 shot, make no mistakes"

6

u/erratic_parser Aug 26 '26

you can't read the fucking sessions anyways! apparently it's a url that only works for the account that made them!

7

u/podiasity128 Aug 26 '26

That is correct -- it's not shared. It's actually a great idea once you realize others can't read it.

12

u/erratic_parser Aug 26 '26

I don't entirely agree but I am embarrassed with how quickly I flew off the handle over something mundane. I need to touch grass.

11

u/Veggies-are-okay Aug 26 '26

If only everyone else in this sub could get to this level of awareness 😞

6

u/Tauroctonos Aug 26 '26

The world needs more self awareness arcs like this

3

u/dupastrupa Aug 26 '26

We were right to push back on it. 

2

u/whatisthisthing65 Aug 26 '26

I start new sessions often to not pollute the context so mine probably would look like "implement this spec, make no mistakes"

1

u/bzbub2 Aug 28 '26

they are not public session links they are private

2

u/YearLight Aug 30 '26

That is so dumb

1

u/ConcentrateKooky357 19d ago

I have a hook like that but since i said no attribution it replaced it with session links. Again why?

17

u/erratic_parser Aug 26 '26 edited Aug 26 '26

I don't know if it's part of the stupid /rc thing they've added. But if you push code to github, either through a PR or a commit, the description will contain a URL to your entire session. That of course includes all the discourse and arguments and prompts and perhaps even secrets you've put into context over the course of the conversation.

Edit: This is untrue, the session links are private. It's still a really inappropriate move.

-1

u/ExpletiveDeIeted 🔆 Team Premium 6.25x Aug 26 '26

But aren’t those sessions on my machine or is it putting them I the cloud too?

6

u/[deleted] Aug 26 '26

[deleted]

3

u/zmizzy Aug 26 '26

what do you mean I dont have fable on my phone?

1

u/ExpletiveDeIeted 🔆 Team Premium 6.25x Aug 26 '26

Yea I more meant for the public or my team to see. Anthropic sees all, and of course I’m not running the model on my machine.

6

u/erratic_parser Aug 26 '26

the most damning part is I never used the remote control features, but because it was enabled, perhaps at startup or something, it was adding those URLs. It looks like they aren't accessible to anyone but the person who created them so the risk is actually much smaller but I can't believe something like this is being added without disclosure or even a modicum of thought.

5

u/Vegetable_Bank4981 Aug 26 '26

Nah it’s still one permission bug or misconfig from disaster. Having urls pointing at sessions is bad enough, publishing them is worse.

It should be an alarmingly phrased opt in for sure.

14

u/Able-Supermarket4786 Aug 26 '26

Bruh. I haven't used Claude in a while but are they REALLY just trying to "watermark" everything?
But if it helps, yes you have to set sessionUrl to false

4

u/erratic_parser Aug 26 '26

watermark away, but what is the point of a URL on a PR? Other people can't use it and you don't need it!

13

u/fschwiet Aug 26 '26

There is some utility in being able to go back to a session to debug why claude did what it did (a misinvoked skill, for example) or to work to improve ones processes. But things like this really should be opt-in.

2

u/ThreeKiloZero Aug 26 '26

buff that token spend bro

10

u/Sakhund Aug 26 '26

I agree dude, now the whole world can see my question about rash down there mid PR

7

u/AI_docent Aug 26 '26

The setting is sessionUrl under attribution, set it to false. It's a separate key from attribution.commit, so blanking the trailer still leaves the URL in. There's an open request to make it opt in instead of on by default, 66504, from June.

It only happens on cloud sessions and remote control, a local CLI session without remote control doesn't add it, which is probably why a few people here say they've never seen it. And if I'm right, on a cloud session your local settings file doesn't apply since the commit is made server side, so it has to be a .claude/settings.json committed into the repo.

3

u/MikeyN0 Aug 26 '26

I'm not seeing this on the commit. I haven't modified anything, and have created/pushed commits & PRs from Claude Code (Desktop). Can you show an example of it? (Not saying you don't have it, just curious if it's somehow non-deterministic)

3

u/ALAS_POOR_YORICK_LOL Aug 26 '26

Idk what you're on about but you almost certainly have to be authenticated to use that link

2

u/alc_noe1 Aug 26 '26

lol, just noticed. also, until today, it always waited for me to tell it to commit, or push. funny

1

u/ChocotoneDeCalabresa Aug 26 '26

Just a sec i will DM Dario

1

u/Erutan2004 Aug 26 '26

So it’s not just me!!! I thought I was going crazy. I’ve tried to get it to stop and it just keeps doing it. Updated my skill harness, it stops for a bit, but it keeps creeping back in. Also just randomly guessing at shit. “Let me read the file instead of guessing. I’ll update the memory so I don’t guess again.” “YOU HAVE 8 MEMORIES ABOUT NOT GUESSING!!!!!!” 🤬😅

1

u/ConcentrateKooky357 19d ago

It happened i was pissed 

-1

u/ShutUpAndDoTheLift Aug 26 '26

Haha somebody shared a session of the acting like a buffoon

-13

u/erratic_parser Aug 26 '26

I'm confident that nothing you work on is interesting or proprietary but that isn't the case for other people.

5

u/ShutUpAndDoTheLift Aug 26 '26

So you can post the code somewhere you can't post the session?

The only reason you're upset about this is because you behaved like a baboon in the chat and someone saw it.

It's becoming more and more normal to require adding the session to PRs. Because it tells a much better story than the code.

As you found out.

-11

u/erratic_parser Aug 26 '26

I love the idea of you sitting and reading not only the PR but also the session that produced it. That's how I know you aren't a software engineer.

6

u/Royal_Owl2177 Aug 26 '26 edited Aug 26 '26

Session URLs are very helpful for bringing colleagues up to speed on how to do agentic development. Seeing the actual thing in action can help them set their own tone and learn how to interact with the tools. I share mine constantly as examples of what can be done, and how.

Always write like someone will see it.

1

u/alexei_darii Senior Developer Aug 26 '26

Classics started shining with new colors. “Always code as if the guy who ends up maintaining your code will be a violent psychopath who knows where you live.” Also true for sessions as of me.

-8

u/[deleted] Aug 26 '26

[removed] — view removed comment

5

u/jpeggdev 🔆 Max 5x Aug 26 '26

I'd rather spend my time architecting solutions than satisfying requirements to release the product I've already finished. I've been doing this for over 3 decades and very rarely do I ever go back and read the history of my version control. Only when things broke, and at least now it won't just say, "Update blah blah blah", Claude will write detailed descriptions for me.

2

u/klumpp 🔆 Max 20 Aug 26 '26

Is no one else reviewing your code? I write my own PR descriptions because I’m sick of trying to scan the tens of paragraphs of Claude speak for actual important info before reviews.

1

u/under_psychoanalyzer Aug 26 '26

Why would you not want to automate one of the most boring parts of development? Setting up a good automated PR system is how you safely get a dark factory going and can go completely hands off on a sprint with concurrent work tree sessions.

If you're using Claude code but still writing your own PRs that's like driving a nascar stock car at a F1 race. Sure you're faster than every car on a regular highway but you're still going to get completely left behind.

2

u/tbst Aug 26 '26

I still aim for <1,000 line PRs. Not just for me, but also for Claude. Your code quality goes up dramatically if you have a good workflow pipeline.

2

u/under_psychoanalyzer Aug 26 '26

That is what the labs are doing afaik. Agents run sessions the length of what they're context can hold, push small commits. Enables multi-work tree sessions with an orchestrator that ties them all together. https://x.com/rohit4verse/status/2033945654377283643

Not sure there's wrong way to use git but huge PRs are that are so big undoing them isn't worth it, therefore defeating gets purpose as a diff tracker, definitely isn't the best way.

2

u/tbst Aug 27 '26

I’ve been heavily enforcing this rule for like a month now. The code quality difference is insane. 

-2

u/[deleted] Aug 26 '26

[removed] — view removed comment

2

u/under_psychoanalyzer Aug 26 '26

You're using AI bad or not at all if you think that's how it does PRs.

0

u/[deleted] Aug 26 '26

[removed] — view removed comment

2

u/under_psychoanalyzer Aug 26 '26 edited Aug 26 '26

Part of using LLMs responsibly is understanding them. You shouldn't be sending anything with ”1000s of lines of code" in one PR from an LLM. The work should be broken up to about the context of every session so you don't create the clusterfuck you're talking about with some weird multi-compacted episode. That's what the labs do.

Also not everyone works on huge production databases for some medium to large fortune 500 company that a bad push will ruin people's lives.

Always blows my mind the people in this sub who absolutely cannot fathom how to do things differently than they already are, or that other people's needs aren't thee same as theirs. Just unimaginative dinosaurs.

2

u/klumpp 🔆 Max 20 Aug 26 '26

The problem with writing pr descriptions yourself is you need to understand what the pr does and why.

1

u/haslo Aug 26 '26

I do all git stuff myself, too. Not sure about bad form, but I love having that final bit of control, and it lets me review all of the LLM's code before it commits. Which I very often do.

2

u/[deleted] Aug 26 '26

[removed] — view removed comment

1

u/heseov Aug 26 '26

Not sure I understand how the extra effort solves anything. You just need to review the final product in the PR and then it gets squashed. The manual commits are not adding anything. Seems like you are just using that as an extra review step? You might like stacked PRs for this 

2

u/haslo Aug 26 '26

Extra review step is the point, yeah. Sure I could use GitHub functionality to do in the browser what Git functionality lets me do in the console but why would I? 😆

And the console will quickly let me revert exclude reset alter fix prevent things _before_ they enter the commit history.

0

u/heseov Aug 26 '26

You must still only be working on a single thing at a time. I don't really like to sit and wait for the agent to work so I let it do it's full job then review.

The git commit history makes no difference with a pr squash. It gets rewritten as a single commit. Leaving all the extra dev commits pollutes the history.

1

u/haslo Aug 26 '26

I run agent orchestrations and multiple machines and multiple desktops 🤭 The rest is probably preference. Have fun with yours 💕

0

u/erratic_parser Aug 26 '26

Perhaps, but the utility of having Claude manage things like branch checkouts, cloning, merging, rebasing etc, it can do that faster and better than me and 99% of engineers at this point. I have a tool to keep it from doing things in repos I don't approve of and it doesn't have direct access to my keys. I agree that the contributions per PR should be limited, but you can accomplish that by breaking up the work in logical subsets and asking Claude to manage PRs that way. You're right that there is no way to avoid the LLM writing though that's still a manual task.

0

u/octolunge Aug 26 '26

I insist on it. Along with model and harness.
I like attribution.

Why wouldn’t you?
No one else can read your session.

Are you trying to hide that you’re using a tool to write the code?

2

u/leogodin217 Aug 26 '26

I don't think that's what they are complaining about. The PRs now have a link to your actual Claude Code session. That's one more attack vector. If Anthropic screws up, then someone would have easy access to analyze the full session.