anthropics / anthropics/claude-code

[BUG] ask permission rule for Bash(git push *) not triggering confirmation prompt

Offen
#87,773 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
area:permissions bug platform:macos stale
Vorherrschende Sprache
Python
Sterne
145k
Forks
23.1k
PR-Merge-Kennzahlen
PR-Kennzahlen ausstehend

Beschreibung

### Preflight Checklist

- [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet
- [x] This is a single bug report (please file separate reports for different bugs)
- [x] I am using the latest version of Claude Code

### What's Wrong?

Description

Environment
- Claude Code version: (run claude --version to get this)
- OS: macOS 24.6.0

What happened
I have the following rule in .claude/settings.json:

"ask": ["Bash(rm *)", "Bash(mv *)", "Bash(git push *)"]

Claude ran git push twice in the same session without triggering a confirmation prompt. The ask rule was silently bypassed.

Expected behavior
Claude should pause and ask for user confirmation before executing any command matching Bash(git push *).

Actual behavior
git push ran without any prompt. The commands that executed were:
git push
(plain push with no additional arguments)

Steps to reproduce
1. Add "Bash(git push *)" to the ask array in .claude/settings.json
2. In a session, ask Claude to push a branch
3. Observe that git push runs without a confirmation prompt

Additional context
The * glob may not be matching a bare git push with no trailing arguments, which could explain why the rule isn't firing. If the pattern requires at least one argument after push, a bare git push would slip through.

---
That last "Additional context" line is worth including — it gives the maintainers a plausible root cause to investigate (glob matching behavior on commands with no trailing args).

### What Should Happen?

Claude should pause and ask for user confirmation before executing any command matching Bash(git push *).

### Error Messages/Logs

```shell

```

### Steps to Reproduce

1. Add "Bash(git push *)" to the ask array in .claude/settings.json
2. In a session, ask Claude to push a branch
3. Observe that git push runs without a confirmation prompt

### Claude Model

None

### Is this a regression?

Yes, this worked in a previous version

### Last Working Version

_No response_

### Claude Code Version

2.1.145 (Claude Code)

### Platform

Anthropic API

### Operating System

macOS

### Terminal/Shell

Terminal.app (macOS)

### Additional Information

The * glob may not be matching a bare git push with no trailing arguments, which could explain why the rule isn't firing. If the pattern requires at least one argument after push, a bare git push would slip through.

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Rechercherichtung

Start with .claude/settings.json and reproduce the reported ask rule using a bare `git push`, after checking the installed version with `claude --version`. Trace the permission matching entry point for Bash commands and compare bare `git push` with commands that have trailing arguments; done means the rule consistently triggers a confirmation prompt before the push runs.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
git, shell
Bereich
cli, security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Aktiv
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
64/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.