anthropics / anthropics/claude-code
[BUG] Permission/privacy messages say THAT files are accessed, but not WHICH — collapsed UI hides the target path
- 主要言語
- Python
- スター
- 145k
- フォーク
- 23.1k
- PR マージ指標
- PR 指標を取得中
説明
### Preflight Checklist
- [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet
- [x] This is a single bug report (please file separate reports for different bugs)
- [x] I am using the latest version of Claude Code
### What's Wrong?
When Claude Code accesses the filesystem (or triggers an OS privacy prompt), the user-facing surface often shows only a generic status — "Reading files…", "Ran N commands", or a macOS folder-category dialog — without the concrete path being accessed. The full tool call with its arguments exists in the transcript, but the collapsed conversation view and the system-level messages do not surface it. The user is effectively approving or observing access blind.
### What Should Happen?
1. Collapsed tool-call rows always show the target: the file path for Read/Edit/Write, the command for Bash — not just a verb and a count.
2. When an OS privacy dialog fires (macOS TCC), the conversation UI should simultaneously show which tool call and which concrete path triggered it — the OS dialog itself is folder-category-granular only.
3. Optionally: a built-in, user-owned access log (path + tool + timestamp) that does not depend on transcript retention.
### Error Messages/Logs
```shell
```
### Steps to Reproduce
1. Run an agent session in auto permission mode (or acceptEdits) in the desktop app.
2. Ask Claude to read or edit several files, including files outside the project directory.
3. Watch the collapsed conversation view: tool rows render as "Reading files…" / "Ran N commands" without the concrete paths.
4. If a macOS TCC privacy dialog appears (e.g. Documents folder access), note it names only the folder category — and the conversation UI adds no information about which path or tool call triggered it.
5. The concrete paths are only discoverable by expanding the full transcript afterwards.
### Claude Model
Other
### Is this a regression?
Yes, this worked in a previous version
### Last Working Version
_No response_
### Claude Code Version
1.32352.1
### Platform
Anthropic API
### Operating System
macOS
### Terminal/Shell
iTerm2
### Additional Information
_No response_
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
調査の方向性
Start by reproducing the issue in the desktop app using auto permission mode or acceptEdits, then compare collapsed tool-call rows with the expanded transcript and the macOS TCC dialog. Trace where the collapsed conversation view renders Read/Edit/Write and Bash calls. Done means the collapsed view identifies concrete targets and privacy prompts are associated with the triggering tool call and path.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- macos
- 領域
- cli, desktop, security
- issue の種類
- バグ
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 活発さ
- 活発
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 35/100