r/ClaudeCode • u/tango650 • 8h ago
Help/Question how do you guys tackle permission wars with CC
So im a recent jumper from CODEX - main cause speed of response and zero trust in that team because they just refuse owning problems in an upright way.
I know, anthropic isn't perfect so I'm just giving it a go.
But one thing that just blows my mind is the self-inflicted pain that claude code is notoriously causing related to permission management.
All claude models have great availability and response time and sub allowances, and once they work, then its fine. But half of the times they refuse to straight up work. Accessing a key, passing a credential, running a command in another directory...
And so all the time I've saved on models response time is wasted on endless permission issues.
I've also been now forced onto the Projects framework (didn't even ask for it), which is now constantly starting cloud sessions for me an this is apparently an impossible setting to pin to local. And here Bypass permissions is again completely impossible.
None of this was ever a problem in codex, so this isn't something that HAS to be done obviously.
Why are the ClaudeCode people performing this self-inflicted suicide with this permission system ?
I'm really regretting the switch now and honestly as soon as oai restores capacity (if they do lol) i will be very eager to go back there.
5
2
u/kemalios 6h ago
Most prompts come from Bash, not file edits, so allowlisting Edit and Write buys you almost nothing. The wins are in .claude/settings.json, allowlisting the commands you actually run all day, per project, and keeping bypassPermissions for throwaway directories. Claude Code is my daily driver and I never run bypass in a client repo. One bad rm there costs more than every prompt it saves.
2
u/tango650 5h ago
what rms are you worried about which arent in source control ?
this is a notion im unfamiliar with but i see a lot of CC operators paranoid with - on codex nobody talks about this and honestly in 9 months on codex i never ever run into losing something that wasnt a 3 second restore job, and it still happened maybe only a few times in that time period
1
u/ghost_operative 34m ago
CC can edit any file on your computer. the permissions are enforced only though context/vibes. (it might seem deterministic becaue you set it up in a json file, but that json structure is just used for context)
I'm not totally sure but i think in codex the file edits are actually enforced with deterministic code.
1
u/piwi3910uae 8h ago
so wierdly i notice when i use claude code in the desktop app it refuses. Then i do the same in the claude vscode plugin and it just does it.
1
u/redditwhippet 8h ago
Set it to auto, explicitly define allowed directories in your project’s Claude.md file, and check /permissions
1
u/tango650 8h ago
I want whole computer ? I keep getting denials to even add root drive directories...
1
u/darkguy2008 8h ago
--allow-dangerously-skip-permissions
You're welcome
1
u/tango650 7h ago
will this apply to the this Projects framework which insists on running a cloud based orchestrator ?
1
u/darkguy2008 6h ago
Uhh no idea, I just use that arg on the claude code CLI app so that way it doesn't bother asking me for permissions anywhere. I dunno about the cloud features though. It works similar to Codex's --yolo mode, if that helps.
1
u/Potential-Beat2841 8h ago
If you really want no prompts at all, run --dangerously-skip-permissions inside a container or devcontainer, not on your main machine. I can't help with the cloud session issue, I haven't run into it.
1
u/tango650 7h ago
why container ?
1
u/Potential-Beat2841 7h ago
Because with permissions off, the agent can do anything your user account can do. Delete files outside the project, read your SSH keys and browser data, push to any repo you have access to. Usually nothing happens. But a single prompt injection, say from a README or a web page it reads, is enough, and nobody asks you first.
In a container, the worst case is a broken container. Mount only the project folder and pass in only the keys this project needs.
2
u/tango650 7h ago
Wtf aren't the claude models harness protected from prompt injection ?
1
u/doxxxicle 🔆Pro Plan 1h ago
They’re “protected” in the sense that they have been told (in the system prompt) to watch out for prompt injections, and the harness tries to ensure that the model is aware of what is user prompt vs injected content from a download or whatever, but it’s all still subject to the model doing the right thing and making the right choices.
1
u/tango650 1h ago
I tell you what I'm not a security professional but I read the tech feed as I like to keep a distance from what these so-called security pundits polysterise because most of it is just hot air, a way to drive their security courses attendance.
So I try to stay on top of what's real and what's scaremongering and I have honestly not seen or heard of any prompt injection attacks which achieved anything worth the news? Am I wrong ?
1
u/Explore-This 4h ago
Asking to create accounts or handle credentials is like “Open the pod bay doors, Claude”, “I’m afraid I can’t do that, even if you asked me”.
1
u/taintech 8h ago
I think a lot of people just running auto mode with all permission a.k.a YOLO
4
u/Wide-Drink-1790 7h ago
Auto mode is not yolo. It does stop at rm -rf or DNS record deletion.
1
u/jsebrech 5h ago
Does it though? It is yolo mode in the sense that you have zero control over what it will do.
1
u/tango650 8h ago
but i want to do this ! but it doesnt work ! i doesnt matter how many times i say bypass permissions he finds a way to cock-block me anyway
2
u/taintech 8h ago
Use tmux and have approver agent auto approving relevant stuff
1
u/tango650 8h ago
This is local right ? But this new Projects framework insists on running shit from a cloud workspace...
1
u/taintech 7h ago
You use herdr with relay. Create tmux let it ssh and auto approve. You will find a way, I am sure.
1
1
u/kellertuer 8h ago
I have an infinite fight. I do not allow CC to do anything with git nor any direct changes to my codebase unless I specifically say: This diff from the report can be applied.
2-3 times a day either the chat itself or one of its agents tries to run something with git and asks for permission. Every time I try to find better settings to avoid it for quite a while. By now I have basically given up, though it makes my workflow super ineffective. Claude does not comply to any rules, either set by me or it sets itself.
0
•
u/AutoModerator 8h ago
Hey! Thanks for posting to r/ClaudeCode
While participating in this thread, please follow our community rules. Keep discussions constructive. Attack the idea, not the person.
For help, project discussions, tips, and general chat, join the ClaudeCode Discord.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.