added settings

This commit is contained in:
bastien
2026-04-02 15:59:00 +02:00
parent e72d72ce29
commit a145e3cc03
8 changed files with 678 additions and 4 deletions
+106
View File
@@ -0,0 +1,106 @@
# ============================================================
# .claudeignore — files Claude cannot read or use as context
# Same syntax as .gitignore
# ============================================================
# ---- Secrets & credentials --------------------------------
.env
.env.*
!.env.example
secrets/
*.pem
*.key
*.p12
*.pfx
*.jks
credentials
credentials.json
service-account*.json
*-credentials.json
.netrc
.pgpass
.my.cnf
# ---- SSH --------------------------------------------------
.ssh/
id_rsa*
id_ed25519*
*.pub
# ---- Cloud provider credentials ---------------------------
.aws/
.azure/
.gcloud/
gcloud-credentials*
# ---- Build artifacts & caches ----------------------------
node_modules/
dist/
build/
.next/
.nuxt/
out/
target/
__pycache__/
*.pyc
.pytest_cache/
.mypy_cache/
.ruff_cache/
*.egg-info/
.eggs/
vendor/
.cargo/registry/
.gradle/
.m2/
# ---- Binary & media files --------------------------------
*.png
*.jpg
*.jpeg
*.gif
*.webp
*.ico
*.svg
*.mp4
*.mp3
*.pdf
*.zip
*.tar
*.tar.gz
*.tgz
*.rar
*.7z
*.dmg
*.exe
*.dll
*.so
*.dylib
*.wasm
# ---- IDE & OS --------------------------------------------
.idea/
.vscode/
*.swp
*.swo
*~
.DS_Store
Thumbs.db
desktop.ini
# ---- Logs & local databases ------------------------------
*.log
logs/
*.sqlite
*.sqlite3
*.db
# ---- Lock files (optional — remove if you want Claude to read them) --
# package-lock.json
# yarn.lock
# Cargo.lock
# poetry.lock
# ---- Large generated files --------------------------------
coverage/
.nyc_output/
*.lcov
+132
View File
@@ -0,0 +1,132 @@
# Claude Code — Settings Reference
## Where each file goes
```
~/.claude/
├── settings.json ← home-settings.json (renamed) — global, NEVER commit
│
mon-projet/
└── .claude/
├── settings.json ← settings.json — project rules, commit to git
└── settings.local.json← settings.local.json — personal, gitignored
```
Add to your project `.gitignore`:
```
.claude/settings.local.json
```
---
## Precedence (highest → lowest)
```
managed-settings.json system-wide, cannot be overridden
└── CLI flags --allowedTools, --disallowedTools (session only)
└── settings.local.json personal local
└── settings.json project (team)
└── ~/.claude/settings.json global user
```
**DENY always wins over ALLOW, regardless of level.**
---
## What goes where
| Rule type | File |
|---|---|
| Deny secrets, SSH, rm -rf, sudo | `~/.claude/settings.json` |
| Deny git push --force, curl\|bash | `~/.claude/settings.json` |
| Ask git push, docker run, deploy | `~/.claude/settings.json` |
| Ask package managers (brew, apt) | `~/.claude/settings.json` |
| Allow git read-only, ls, cat, grep | `~/.claude/settings.json` |
| Allow npm/cargo/make/pytest... | `.claude/settings.json` (project) |
| Ask psql, mysql, redis-cli | `.claude/settings.json` (project) |
| Allow specific WebFetch domains | `.claude/settings.local.json` |
| Personal additionalDirectories | `.claude/settings.local.json` |
---
## defaultMode values
| Value | Behavior | When to use |
|---|---|---|
| `default` | Prompts on first use of each tool | Normal development |
| `acceptEdits` | Auto-accepts file edits, prompts for Bash | Trusting sessions |
| `plan` | Read-only — Claude plans, cannot execute | Code review, audit |
| `bypassPermissions` | Skips all prompts — **dangerous** | CI/CD only, sandboxed env |
Disable bypass permanently (set in `~/.claude/settings.json`):
```json
{ "permissions": { "disableBypassPermissionsMode": "disable" } }
```
---
## Rule syntax
### Bash
```json
"Bash(git status)" // exact match
"Bash(npm run test:*)" // wildcard suffix
"Bash(git push*)" // prefix match
"Bash(curl * | bash)" // pipe pattern — block code injection
```
### Read / Write / Edit — gitignore syntax
```json
"Read(**/.env)" // any .env in any subdirectory
"Read(**/secrets/**)" // anything inside secrets/
"Read(src/**/*.ts)" // all .ts under src/
"Write(**/*.key)" // deny writing any .key file
```
### WebFetch
```json
"WebFetch(domain:docs.rs)" // specific domain only
"WebFetch" // all web fetches (no sub-pattern)
```
### WebSearch
```json
"WebSearch" // no sub-patterns supported
```
### Agent / Skill / MCP
```json
"Agent(explorer)"
"Skill(deploy *)"
"mcp__github__*" // all tools from github MCP server
"mcp__playwright__navigate"
```
---
## Security notes
- `Read(**/.env)` only blocks the Read tool.
`Bash(cat .env)` bypasses it unless you also deny that Bash command.
→ Use `.claudeignore` for hard file exclusion.
- `disableBypassPermissionsMode: "disable"` prevents switching to
bypass mode mid-session — set it in `~/.claude/settings.json`.
- Prefer `ask` over `allow` for anything touching external systems
(git push, deploy, database commands, package install).
- `deny` rules in `~/.claude/settings.json` cannot be overridden
by project-level `allow` rules — deny always wins globally.
---
## managed-settings.json (enterprise)
Cannot be overridden by any user or project setting.
| OS | Path |
|---|---|
| Windows | `C:\ProgramData\ClaudeCode\managed-settings.json` |
| macOS | `/Library/Application Support/ClaudeCode/managed-settings.json` |
| Linux | `/etc/claude-code/managed-settings.json` |
+81
View File
@@ -0,0 +1,81 @@
{
"_readme": "Project-level settings — commit this file. Extends ~/.claude/settings.json. Only put project-specific rules here.",
"permissions": {
"allow": [
"Bash(npm run *)",
"Bash(npm install)",
"Bash(npm ci)",
"Bash(yarn *)",
"Bash(pnpm *)",
"Bash(cargo build*)",
"Bash(cargo test*)",
"Bash(cargo run*)",
"Bash(cargo check*)",
"Bash(cargo clippy*)",
"Bash(cargo fmt*)",
"Bash(cargo clean*)",
"Bash(go build *)",
"Bash(go test *)",
"Bash(go run *)",
"Bash(go fmt *)",
"Bash(go mod *)",
"Bash(go vet *)",
"Bash(go generate *)",
"Bash(python *)",
"Bash(python3 *)",
"Bash(pytest *)",
"Bash(pip install *)",
"Bash(pip install -r *)",
"Bash(uv *)",
"Bash(ruff *)",
"Bash(black *)",
"Bash(mypy *)",
"Bash(alembic *)",
"Bash(make)",
"Bash(make *)",
"Bash(php *)",
"Bash(composer *)",
"Bash(wp *)",
"Bash(flutter *)",
"Bash(dart *)",
"Bash(docker build *)",
"Bash(docker ps*)",
"Bash(docker images*)",
"Bash(docker logs *)",
"Bash(docker stop *)",
"Bash(docker rm *)",
"Bash(node *)",
"Bash(ts-node *)",
"Bash(tsx *)",
"Bash(npx *)",
"Bash(norminette*)"
],
"ask": [
"Bash(make deploy*)",
"Bash(npm run deploy*)",
"Bash(cargo publish*)",
"Bash(psql *)",
"Bash(mysql *)",
"Bash(mongosh *)",
"Bash(redis-cli *)"
],
"deny": []
}
}
+32
View File
@@ -0,0 +1,32 @@
{
"_readme": "Personal local overrides — DO NOT commit. Add .claude/settings.local.json to .gitignore. Highest priority after CLI flags.",
"permissions": {
"defaultMode": "default",
"allow": [
"WebFetch(domain:docs.anthropic.com)",
"WebFetch(domain:developer.mozilla.org)",
"WebFetch(domain:docs.rs)",
"WebFetch(domain:pkg.go.dev)",
"WebFetch(domain:pypi.org)",
"WebFetch(domain:npmjs.com)",
"WebFetch(domain:crates.io)",
"WebFetch(domain:docs.python.org)",
"WebFetch(domain:react.dev)",
"WebFetch(domain:nextjs.org)",
"WebFetch(domain:vuejs.org)",
"WebFetch(domain:laravel.com)",
"WebFetch(domain:flutter.dev)"
],
"deny": [],
"ask": [],
"additionalDirectories": [
]
}
}