anthropics / anthropics/claude-code
Browser pane can't grant local-network/loopback permission, so Duo Desktop device-health check fails (Duo-protected SSO sites unusable)
- Vorherrschende Sprache
- Python
- Sterne
- 145k
- Forks
- 23.1k
- PR-Merge-Kennzahlen
- PR-Kennzahlen ausstehend
Beschreibung
## Summary
In the Claude Code desktop app's built-in Browser pane, signing into a Duo-protected SSO site dead-ends on Duo's **"Allow local network access"** screen. Duo Desktop's device-health check needs Chromium's local-network / "Apps on device" (loopback) site permission, and the pane offers no way to grant it — so any site behind Duo Desktop policies is unusable in the pane.
## Environment
- Claude Code desktop, macOS (Darwin 25.6.0)
- Browser pane UA: `Claude/1.40609.1 Chrome/148.0.7778.280` (brand: Chromium)
- Site: Notion (app.notion.com) via Microsoft Entra SSO → Duo 2FA with Duo Desktop device-health policy
## Steps to reproduce
1. Open a Duo-protected SSO site in the Browser pane (e.g. `app.notion.com` for a workspace on Entra SSO + Duo).
2. Start sign-in and reach the Duo prompt.
3. Duo shows "Allow local network access — Duo uses local network access to communicate with Duo Desktop", with instructions to click the browser's site-information icon and toggle *Local network access*.
## What goes wrong
- The pane has no address bar / site-information UI, so the toggle Duo points at doesn't exist.
- `chrome://settings/...` URLs are refused by the pane, so the permission can't be reached that way either.
- The pane doesn't honor Chrome enterprise policy (`LocalNetworkAccessAllowedForUrls`), which is how our MDM fixes regular Chrome — the embedded Chromium isn't Google Chrome, so the policy doesn't apply.
- Duo runs this check *before* offering alternate factors (Push / passcode), so there's no fallback within the prompt.
Background on the browser change that triggers this (Chrome 142+/145+ local-network permission prompt): https://help.duo.com/s/article/9540
## Impact
Any organization enforcing Duo Desktop device-health / Trusted Endpoints policies can't sign into SSO sites in the Browser pane at all. This is a common enterprise setup, and the docs (the Desktop page's "browse external sites" section mentions popup sign-in flows like Google OAuth) don't note the limitation.
## Requested
One of:
- Surface the Chromium local-network / loopback permission prompt in the pane so the user can grant it, or
- A setting to allowlist origins for local-network access (e.g. `[*.]duosecurity.com`), or
- At minimum, document the limitation.
Beitragsleitfaden
Für dieses Repository ist kein Beitragsleitfaden indexiert
Rechercherichtung
The issue identifies the Claude Code desktop Browser pane and Chromium local-network access as the entry points; no repository files or tests are named. First reproduce the Duo-protected SSO flow on macOS, then determine whether the pane can expose or allowlist the permission. Done means Duo device-health checks can complete in the pane, or the limitation is documented if support is not feasible.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- macos
- Bereich
- authentication, desktop, security
- Issue-Typ
- Feature
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Aktivitätsstatus
- Aktiv
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 30/100