feat(hooks): config-protection PreToolUse guards quality-gate files

Blocks Edit/Write to guardrails (settings.json + .claude/settings*, lib/gitflow.sh, .githooks/*, doctor.sh, hooks/*.sh self-guard, lib/tests/*, lint) so a gate can't be weakened to pass an error. Bypass = one-shot sentinel .claude/.config-edit-ok (non-empty reason, logged+consumed), not an env-var. Adaptation from the ECC second-look (BDR-047 corrob): own bash idiom, not ECC's Node dispatcher. shellcheck clean, test 20/20.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
This commit is contained in:
Bastien Chanot
2026-07-03 15:29:20 +02:00
co-authored by Claude Opus 4.8
parent 18c37a5505
commit 55347445cc
3 changed files with 132 additions and 0 deletions
+10
View File
@@ -245,6 +245,16 @@
"command": "bash ~/.claude/hooks/rtk-rewrite.sh"
}
]
},
{
"matcher": "Edit|Write|MultiEdit",
"hooks": [
{
"type": "command",
"command": "bash ~/.claude/hooks/config-protection.sh",
"timeout": 5
}
]
}
],
"UserPromptSubmit": [