Practice — Settings, Permissions & Hooks (17 questions)
Debugging a Permission Rule That Won't Take Effect Permalink →
Your team's .claude/settings.json contains:
{
"permissions": {
"allow": ["Bash(aws s3 ls)"],
"deny": ["Bash(aws *)"]
}
}
An engineer reports that aws s3 ls still prompts for approval every
time, even though they explicitly allowed it.
- Explain exactly why the
allowrule has no effect here. - Rewrite the configuration so that
aws s3 lsruns without a prompt while every otherawssubcommand still requires approval. - A teammate suggests moving the
allowrule into.claude/settings.local.jsoninstead, reasoning that local settings have higher precedence than project settings. Would that fix it? Why or why not?
Share this question
Which Hook Event Can Actually Prevent the Write Permalink →
Your team keeps a machine-generated .env.production file that Claude
should never be allowed to modify, no matter what a prompt or a
compromised instruction asks for. You want to register a hook that,
when it exits with status 2, guarantees the edit never lands on disk
in the first place — not one that merely notices the change after the
fact.
Which hook event should this guardrail be registered on?
Share this question
Shrinking a Noisy Test Run Before Claude Ever Sees It Permalink →
Your npm test output floods the context with thousands of lines of
passing-test noise on every run.
What mechanism lets you filter that output down to just the failures before it ever reaches Claude's context?
Share this question
Four Ways to Make a Check Actually Block the Stop Permalink →
You want a verification check to do more than run once — you want it to actually gate whether Claude Code is allowed to consider the task done, scaling up as a run becomes less attended.
Put these in the order of escalating rigor this subject describes: a
Stop hook, a one-off prompt instruction, a verification subagent, a
/goal condition.
Share this question
The Number of Blocks Before a Stop Hook Gets Overridden Permalink →
You've set up a Stop hook that blocks the turn from ending until your check passes, intending it as a hard gate on an unattended run.
After how many consecutive blocks does Claude Code override it and let the turn end anyway?
Share this question
The CLAUDE.md Difference Between Two Ways to Grant Cross-Package Access Permalink →
A task needs to edit both packages/api/ and a shared types package
outside your current scope. You could add additionalDirectories to
settings, or pass --add-dir at launch.
What's the concrete difference between them?
Share this question
The One-Character Difference That Changes What a Rule Matches Permalink →
You write Bash(git diff*) in permissions.allow, intending it to
match git diff and its variants. A teammate points out it also
silently matches git diff-index.
What's the actual fix?
Share this question