anthropics / anthropics/claude-code
[BUG] ask permission rule for Bash(git push *) not triggering confirmation prompt
- Vorherrschende Sprache
- Python
- Sterne
- 145k
- Forks
- 23.1k
- PR-Merge-Kennzahlen
- PR-Kennzahlen ausstehend
Beschreibung
### Preflight Checklist
- [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet
- [x] This is a single bug report (please file separate reports for different bugs)
- [x] I am using the latest version of Claude Code
### What's Wrong?
Description
Environment
- Claude Code version: (run claude --version to get this)
- OS: macOS 24.6.0
What happened
I have the following rule in .claude/settings.json:
"ask": ["Bash(rm *)", "Bash(mv *)", "Bash(git push *)"]
Claude ran git push twice in the same session without triggering a confirmation prompt. The ask rule was silently bypassed.
Expected behavior
Claude should pause and ask for user confirmation before executing any command matching Bash(git push *).
Actual behavior
git push ran without any prompt. The commands that executed were:
git push
(plain push with no additional arguments)
Steps to reproduce
1. Add "Bash(git push *)" to the ask array in .claude/settings.json
2. In a session, ask Claude to push a branch
3. Observe that git push runs without a confirmation prompt
Additional context
The * glob may not be matching a bare git push with no trailing arguments, which could explain why the rule isn't firing. If the pattern requires at least one argument after push, a bare git push would slip through.
---
That last "Additional context" line is worth including — it gives the maintainers a plausible root cause to investigate (glob matching behavior on commands with no trailing args).
### What Should Happen?
Claude should pause and ask for user confirmation before executing any command matching Bash(git push *).
### Error Messages/Logs
```shell
```
### Steps to Reproduce
1. Add "Bash(git push *)" to the ask array in .claude/settings.json
2. In a session, ask Claude to push a branch
3. Observe that git push runs without a confirmation prompt
### Claude Model
None
### Is this a regression?
Yes, this worked in a previous version
### Last Working Version
_No response_
### Claude Code Version
2.1.145 (Claude Code)
### Platform
Anthropic API
### Operating System
macOS
### Terminal/Shell
Terminal.app (macOS)
### Additional Information
The * glob may not be matching a bare git push with no trailing arguments, which could explain why the rule isn't firing. If the pattern requires at least one argument after push, a bare git push would slip through.
Beitragsleitfaden
Für dieses Repository ist kein Beitragsleitfaden indexiert
Rechercherichtung
Start with .claude/settings.json and reproduce the reported ask rule using a bare `git push`, after checking the installed version with `claude --version`. Trace the permission matching entry point for Bash commands and compare bare `git push` with commands that have trailing arguments; done means the rule consistently triggers a confirmation prompt before the push runs.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- git, shell
- Bereich
- cli, security
- Issue-Typ
- Bug
- Schwierigkeit
- 3/5
- Geschätzter Aufwand
- 1-2 Tage
- Aktivitätsstatus
- Aktiv
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 64/100