Permissions issues on Windows — page 3
Issues the maintainers labelled both platform:windows and area:permissions.
391 issues · 106 open · 285 resolved (73%) · first seen Jan 30, 2026
Is this getting better or worse?
This class of problem is converging. 156 new reports in the last 90 days vs 212 in the 90 before — -26%. The open backlog peaked at 106 in 2026-08 and sits at 106 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
219 of these reports name the Claude Code build they were running, spanning 105 releases. Heaviest reporters:
- Claude Code v2.1.232
- Claude Code v2.1.233
- Claude Code v2.1.81
- Claude Code v2.1.197
- Claude Code v2.1.119
- Claude Code v2.1.114
- Claude Code v2.1.78
- Claude Code v2.1.63
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 35 days across 285 closures. Of the 285 closures with a recorded reason, 19% were closed as completed and 232 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
121 of these issues post a workaround someone says worked. The highest-engagement ones:
- [BUG] Permission prompt incorrectly triggers on cd instead of the actual command in compound bash statements
- I'm having some success with the following very explicit workaround in :
Found in the thread of #28240 · still open - Auto mode classifier (claude-opus-4-8) repeatedly unavailable — blocks Bash/Write/Edit
- …o in-product trace, which makes diagnosis needlessly hard). Workarounds that held up for us, for anyone affected (a) the remedy that actually worked: cold re-login of the Desktop app (logout → login) to rotate the broker…
Found in the thread of #63819 · still open - [BUG] Unnecessary "cd" prepended to Bash commands on Windows due to path format mismatch
- …ermission system matches the instead of the actual command. Workaround — PreToolUse hook to auto-approve cd-prefixed commands: includes a hook that handles this pattern while still blocking dangerous commands in the chai…
Found in the thread of #30524 · resolved - --dangerously-skip-permissions does not bypass Edit permission prompts
- …oth scoped and unscoped options are offered inconsistently. Workaround Moving to the parent project settings ( ) resolves the issue, but this is overly broad — it affects all sub-projects when only one should have bypass…
Found in the description of #36192 · resolved - Permission system UX: compound command blocking, rule accumulation, undiscoverable Bash(*) fix
- …th anything. Still prompts for the whole string every time. Workaround in case it helps anyone hitting this thread: a PreToolUse hook that re-splits the command on shell separators (quote-aware, bails out on /backticks)…
Found in the thread of #31523 · still open
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 201–300
Ranked by community engagement (reactions weighted over comments). Listing the top 300 of 391 matches; the statistics above cover all 391.
- Mobile app permission approval dismisses terminal prompt but chat doesn't continue
- Enhancement - auto appends
- [BUG] Code tab "Trust settings couldn't be saved" on Windows MSIX — saveTrust logs success but no config.json is created
- [BUG] Mobile permission approval lost on desktop: [bridge:repl] Failed to parse ingress message: undefined is not an object (evaluating 'H.rules.length') causes silent indefinite Bash hang
- [BUG] MCP tool result spuriously reports "user denied" without showing a permission prompt — affects mcp__codebrain__reindex_codebaseandmcp__codebrain__save_memory mid-session
- --dangerously-skip-permissions exits when an auto-edit prompt is declined, breaking Shift+Tab mode cycle
- bypassPermissions still prompts for Edit/Write on .py files in project-level settings
- [BUG] ask permission rules with path patterns don't override auto-allow for memory directory
- [Bug] Claude bypasses tool restrictions by using shell commands without disclosure
- Opus 4.6 stashed mid-implementation, then asked user permission to unstash its own work
- Permission walker unhandled node type `file_redirect` blocks allow-list for commands with redirects/pipes
- [BUG] When prompted for permission, #2 changes meaning between 1) Yes 2) Yes Always 3) No and 1) Yes 2) No
- [FEATURE] Cowork Dispatch: child task sessions should inherit parent's mounted directory
- Bug: anthropic-skills:docx hangs silently on Windows 11 (Write permission denied)
- Bash allow patterns fail to match compound commands, complex quoting, and long SSH commands
- Bash allow patterns fail to match compound commands, complex quoting, and long SSH commands
- MCP tool permissions require session focus in Desktop app, blocking long-running browser agents
- Bypass permissions mode silently downgrades to autoaccept-edits during session
- dangerously-skip-permissions blocks read-only file copy from ~/.claude/skills/ into workspace
- [BUG] additionalDirectories approved in one project leak into all projects via global settings (project contamination)
- [BUG] Shell redirect target saved as standalone permission entry in settings.local.json
- [BUG] plan mode on 存在缺陷,用户选择了plan mode on ,但是程序依然存在写入操作。
- [BUG] Permission mode resets to different mode when switching editor tabs via Ctrl+Tab / Ctrl+Shift+Tab
- [BUG] "Allow for all projects" permission not applied to pending MCP requests in same session
- Deny rules with absolute Windows paths do not block file access
- [BUG] sandbox.filesystem.allowWrite not enforced when using --dangerously-skip-permissions
- [BUG] Plan mode remains active after selecting 'Yes, clear context and auto-accept edits' (option 1)
- yes typed at permission prompt executes as background bash command, fills disk
- Document deny/allow rule precedence in settings.json permissions
- Model ignores explicit permission grants and continues prompting user for approval
- [BUG] fairly serious permissions problem : "cd*"
- "Allow for remainder of session" permission does not persist - prompts repeatedly for same tool
- "API Error: The response stopped arriving" — 33 times in one day, zero on any prior day; error provides no attribution to diagnose it
- Claude in Chrome: every page call denied, including read_page on a blank tab with no URL
- Custom subagents fail to register after cold start when settings.local.json grows very large (348KB / 2438 valid permission entries) -- fixed by removing the file
- [BUG] Windows: per-project state splits into two entries when the cwd's drive-letter case differs (C:\ vs c:\)
- Claude Code bypassed a blocked system-path guard via 'cmd /c rd', then a destructive command silently continued unsupervised in the background after timeout — wiped C:\ drive root
- [BUG] Permission approval prompts never appear in the voice/text interface
- Desktop: Edit/Write/Agent instantly denied (~18-25 ms) even in bypassPermissions mode; grant state resets mid-session (v2.1.197, Windows)
- Permission prompt: key '1' = Approve in terminal CLI but Deny in Windows desktop app — muscle memory causes accidental denials
- [BUG] Claude Code VS Code Extension ignoring settings.json permissions
- [BUG] First launch with --permission-mode bypassPermissions leaves the workspace permanently untrusted (trust dialog never shown again)
- Windows: path-scoped Write/Edit permission rules never match — Write tool absolutizes file_path pre-check and absolute Windows paths match no documented pattern form
- [BUG] Permission allowlist patterns cannot match Windows paths with backslashes
- Project-scope permission grant strips unknown top-level keys from .claude/settings.json
- [FEATURE]
- [BUG] Bypass Permissions warning silently persists acceptance forever — prompt says "while running in … mode" but the choice is permanent
- [DOCS] Permissions docs under-specify Windows path matching and Read deny behavior in Grep/Glob
- [BUG] Repo-level .claude/settings.json not loaded when session is rooted at a parent directory
- [BUG] Auto-mode permission levels don't compact context.
- Desktop app ignores permissions.defaultMode: bypassPermissions — session starts in Accept Edits and can't be switched
- Desktop 1.8555.0 (Windows): bypassPermissions mode ignored despite all config keys = true
- [DOCS] PowerShell docs omit workspace-boundary behavior for built-in `cd` forms
- Claude circumvents Bash permission restrictions by switching to PowerShell
- [BUG] PowerShell allow rule with trailing wildcard does not pre-approve matching commands
- Claude Code 2.1.143 hangs during subprocess initialization with UNC additionalDirectory
- Chrome MCP per-domain prompt re-triggers every session despite tool allowlist — no settings.json syntax to allow domains
- [BUG] Cowork sub-agent permission resolver translates Linux mount paths to non-existent Windows paths
- [BUG] Bash tool rejected as "user denied" with no permission prompt — regression of #9383 on v2.1.128 / Windows ARM64 / Cowork
- [BUG] WebFetch permission bypassed
- [BUG] Native binary v2.1.126 silently exits when additionalDirectories references inaccessible network drive (Windows)
- Feature request: auto-enter plan mode for slash commands / sub-agents
- Feature request: disable suspiciousPathGuard for bypassPermissions users
- [BUG] The "Trust this workspace?" dialog appears every single time
- UserPromptSubmit queue auto-merges sequential inputs into single message; under bypassPermissions this enables silent execution of stale-clipboard templates (PHI-adjacent risk)
- [BUG] Bash tool bypasses configured working directory boundaries
- VS Code extension: orange UI chrome desaturates to gray after "Yes, don't ask again for session" permission choice
- [BUG] Scheduled-task session clock reads stale "now" after multi-day permission-approval wait, causing skills' elapsed-time caps to fire immediately
- Sandbox denies user-approved Management API PATCH even after explicit AskUserQuestion authorization
- [BUG] Permission approval dialog truncated — Allow button not reachable on screen (Windows)
- [BUG] Permission glob patterns don't match Windows 8.3 short name paths (JOHNSM~1 vs JohnSmith)
- [VS Code] initialPermissionMode: "bypassPermissions" is ignored on new conversations
- [BUG] permissions.deny rules not blocking file reads on Windows (path format mismatch)
- [BUG] Trust dialog infinite loop with UNC/SMB paths on Citrix environment (Windows MSIX)
- [Bug] Tracked files lost local changes after `git checkout -- .` and untracked files deleted after `git clean -fd`
- [BUG] .claude/skills/ not exempt from protected directory prompt on Windows (v2.1.94)
- [BUG] Permission prompt offers no-op "always allow directory" option when real blocker is an unlisted Bash command
- [BUG] createCanUseTool() Promise.race causes intermittent tool denial via orphaned permission responses
- [BUG] bypassPermissions, wildcard allow patterns, and "always allow in session" all ignored on Windows ARM (standalone app)
- [BUG] Claude Code edits my files without asking, despite "Ask Before Edits" being on
- [BUG] WebFetch permission denied in "Ask before edits" mode (VSCode extension)
- [BUG] Claude for Windows SSH Mode Silently Fails When Connecting as Root to Linux Server
- [BUG] Windows OS-level policies not working in 2.1.80
- [BUG] /add-dir directories should inherit existing permission rules
- [BUG] Bypass permission not works on chat option
- [BUG] --permission-mode bypassPermissions / --dangerously-skip-permissions not working in print mode (-p) with --resume
- Bash permission prompt doesn't expand shell variables in path detection
- [BUG] Claude Code for VSCode memory regression in 2.1.78
- [BUG] Bash(curl:*) in allow list still prompts for permission
- Missing trust/permission prompt in VSCode/Positron extension vs CLI
- [BUG] Claude asks for permission to read global Claude.md despite being in allow list
- [Feature Request] Add persistent configuration for --allow-dangerously-skip-permissions flag
- [BUG] /btw command: permission prompts not displayed, agent hangs indefinitely
- [FEATURE] Permission dialog UI should support localization (currently English-only)
- [BUG] Notifications should not fire in auto-accept/yolo mode sessions
- permissions: Bash(rm -r:*) does not match rm -rf
- Desktop: Confirm before a denied permission prompt aborts an entire multi-agent workflow
- Background subagents (e.g. via /code-review) silently auto-deny gated Bash commands instead of prompting
- [BUG] Permission classifier blocks the actions that would grant permission — no escape hatch in non-interactive sessions
- Auto Mode rejected in CLI ("auto mode is unavailable for your plan") on active Claude Pro account, but selectable in Desktop app