forked from bchanot/claude
added settings
This commit is contained in:
@@ -0,0 +1,106 @@
|
||||
# ============================================================
|
||||
# .claudeignore — files Claude cannot read or use as context
|
||||
# Same syntax as .gitignore
|
||||
# ============================================================
|
||||
|
||||
# ---- Secrets & credentials --------------------------------
|
||||
.env
|
||||
.env.*
|
||||
!.env.example
|
||||
secrets/
|
||||
*.pem
|
||||
*.key
|
||||
*.p12
|
||||
*.pfx
|
||||
*.jks
|
||||
credentials
|
||||
credentials.json
|
||||
service-account*.json
|
||||
*-credentials.json
|
||||
.netrc
|
||||
.pgpass
|
||||
.my.cnf
|
||||
|
||||
# ---- SSH --------------------------------------------------
|
||||
.ssh/
|
||||
id_rsa*
|
||||
id_ed25519*
|
||||
*.pub
|
||||
|
||||
# ---- Cloud provider credentials ---------------------------
|
||||
.aws/
|
||||
.azure/
|
||||
.gcloud/
|
||||
gcloud-credentials*
|
||||
|
||||
# ---- Build artifacts & caches ----------------------------
|
||||
node_modules/
|
||||
dist/
|
||||
build/
|
||||
.next/
|
||||
.nuxt/
|
||||
out/
|
||||
target/
|
||||
__pycache__/
|
||||
*.pyc
|
||||
.pytest_cache/
|
||||
.mypy_cache/
|
||||
.ruff_cache/
|
||||
*.egg-info/
|
||||
.eggs/
|
||||
vendor/
|
||||
.cargo/registry/
|
||||
.gradle/
|
||||
.m2/
|
||||
|
||||
# ---- Binary & media files --------------------------------
|
||||
*.png
|
||||
*.jpg
|
||||
*.jpeg
|
||||
*.gif
|
||||
*.webp
|
||||
*.ico
|
||||
*.svg
|
||||
*.mp4
|
||||
*.mp3
|
||||
*.pdf
|
||||
*.zip
|
||||
*.tar
|
||||
*.tar.gz
|
||||
*.tgz
|
||||
*.rar
|
||||
*.7z
|
||||
*.dmg
|
||||
*.exe
|
||||
*.dll
|
||||
*.so
|
||||
*.dylib
|
||||
*.wasm
|
||||
|
||||
# ---- IDE & OS --------------------------------------------
|
||||
.idea/
|
||||
.vscode/
|
||||
*.swp
|
||||
*.swo
|
||||
*~
|
||||
.DS_Store
|
||||
Thumbs.db
|
||||
desktop.ini
|
||||
|
||||
# ---- Logs & local databases ------------------------------
|
||||
*.log
|
||||
logs/
|
||||
*.sqlite
|
||||
*.sqlite3
|
||||
*.db
|
||||
|
||||
# ---- Lock files (optional — remove if you want Claude to read them) --
|
||||
# package-lock.json
|
||||
# yarn.lock
|
||||
# Cargo.lock
|
||||
# poetry.lock
|
||||
|
||||
# ---- Large generated files --------------------------------
|
||||
coverage/
|
||||
.nyc_output/
|
||||
*.lcov
|
||||
@@ -0,0 +1,132 @@
|
||||
# Claude Code — Settings Reference
|
||||
|
||||
## Where each file goes
|
||||
|
||||
```
|
||||
~/.claude/
|
||||
├── settings.json ← home-settings.json (renamed) — global, NEVER commit
|
||||
│
|
||||
mon-projet/
|
||||
└── .claude/
|
||||
├── settings.json ← settings.json — project rules, commit to git
|
||||
└── settings.local.json← settings.local.json — personal, gitignored
|
||||
```
|
||||
|
||||
Add to your project `.gitignore`:
|
||||
```
|
||||
.claude/settings.local.json
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Precedence (highest → lowest)
|
||||
|
||||
```
|
||||
managed-settings.json system-wide, cannot be overridden
|
||||
└── CLI flags --allowedTools, --disallowedTools (session only)
|
||||
└── settings.local.json personal local
|
||||
└── settings.json project (team)
|
||||
└── ~/.claude/settings.json global user
|
||||
```
|
||||
|
||||
**DENY always wins over ALLOW, regardless of level.**
|
||||
|
||||
---
|
||||
|
||||
## What goes where
|
||||
|
||||
| Rule type | File |
|
||||
|---|---|
|
||||
| Deny secrets, SSH, rm -rf, sudo | `~/.claude/settings.json` |
|
||||
| Deny git push --force, curl\|bash | `~/.claude/settings.json` |
|
||||
| Ask git push, docker run, deploy | `~/.claude/settings.json` |
|
||||
| Ask package managers (brew, apt) | `~/.claude/settings.json` |
|
||||
| Allow git read-only, ls, cat, grep | `~/.claude/settings.json` |
|
||||
| Allow npm/cargo/make/pytest... | `.claude/settings.json` (project) |
|
||||
| Ask psql, mysql, redis-cli | `.claude/settings.json` (project) |
|
||||
| Allow specific WebFetch domains | `.claude/settings.local.json` |
|
||||
| Personal additionalDirectories | `.claude/settings.local.json` |
|
||||
|
||||
---
|
||||
|
||||
## defaultMode values
|
||||
|
||||
| Value | Behavior | When to use |
|
||||
|---|---|---|
|
||||
| `default` | Prompts on first use of each tool | Normal development |
|
||||
| `acceptEdits` | Auto-accepts file edits, prompts for Bash | Trusting sessions |
|
||||
| `plan` | Read-only — Claude plans, cannot execute | Code review, audit |
|
||||
| `bypassPermissions` | Skips all prompts — **dangerous** | CI/CD only, sandboxed env |
|
||||
|
||||
Disable bypass permanently (set in `~/.claude/settings.json`):
|
||||
```json
|
||||
{ "permissions": { "disableBypassPermissionsMode": "disable" } }
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Rule syntax
|
||||
|
||||
### Bash
|
||||
```json
|
||||
"Bash(git status)" // exact match
|
||||
"Bash(npm run test:*)" // wildcard suffix
|
||||
"Bash(git push*)" // prefix match
|
||||
"Bash(curl * | bash)" // pipe pattern — block code injection
|
||||
```
|
||||
|
||||
### Read / Write / Edit — gitignore syntax
|
||||
```json
|
||||
"Read(**/.env)" // any .env in any subdirectory
|
||||
"Read(**/secrets/**)" // anything inside secrets/
|
||||
"Read(src/**/*.ts)" // all .ts under src/
|
||||
"Write(**/*.key)" // deny writing any .key file
|
||||
```
|
||||
|
||||
### WebFetch
|
||||
```json
|
||||
"WebFetch(domain:docs.rs)" // specific domain only
|
||||
"WebFetch" // all web fetches (no sub-pattern)
|
||||
```
|
||||
|
||||
### WebSearch
|
||||
```json
|
||||
"WebSearch" // no sub-patterns supported
|
||||
```
|
||||
|
||||
### Agent / Skill / MCP
|
||||
```json
|
||||
"Agent(explorer)"
|
||||
"Skill(deploy *)"
|
||||
"mcp__github__*" // all tools from github MCP server
|
||||
"mcp__playwright__navigate"
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Security notes
|
||||
|
||||
- `Read(**/.env)` only blocks the Read tool.
|
||||
`Bash(cat .env)` bypasses it unless you also deny that Bash command.
|
||||
→ Use `.claudeignore` for hard file exclusion.
|
||||
|
||||
- `disableBypassPermissionsMode: "disable"` prevents switching to
|
||||
bypass mode mid-session — set it in `~/.claude/settings.json`.
|
||||
|
||||
- Prefer `ask` over `allow` for anything touching external systems
|
||||
(git push, deploy, database commands, package install).
|
||||
|
||||
- `deny` rules in `~/.claude/settings.json` cannot be overridden
|
||||
by project-level `allow` rules — deny always wins globally.
|
||||
|
||||
---
|
||||
|
||||
## managed-settings.json (enterprise)
|
||||
|
||||
Cannot be overridden by any user or project setting.
|
||||
|
||||
| OS | Path |
|
||||
|---|---|
|
||||
| Windows | `C:\ProgramData\ClaudeCode\managed-settings.json` |
|
||||
| macOS | `/Library/Application Support/ClaudeCode/managed-settings.json` |
|
||||
| Linux | `/etc/claude-code/managed-settings.json` |
|
||||
@@ -0,0 +1,81 @@
|
||||
{
|
||||
"_readme": "Project-level settings — commit this file. Extends ~/.claude/settings.json. Only put project-specific rules here.",
|
||||
|
||||
"permissions": {
|
||||
|
||||
"allow": [
|
||||
|
||||
"Bash(npm run *)",
|
||||
"Bash(npm install)",
|
||||
"Bash(npm ci)",
|
||||
|
||||
"Bash(yarn *)",
|
||||
"Bash(pnpm *)",
|
||||
|
||||
"Bash(cargo build*)",
|
||||
"Bash(cargo test*)",
|
||||
"Bash(cargo run*)",
|
||||
"Bash(cargo check*)",
|
||||
"Bash(cargo clippy*)",
|
||||
"Bash(cargo fmt*)",
|
||||
"Bash(cargo clean*)",
|
||||
|
||||
"Bash(go build *)",
|
||||
"Bash(go test *)",
|
||||
"Bash(go run *)",
|
||||
"Bash(go fmt *)",
|
||||
"Bash(go mod *)",
|
||||
"Bash(go vet *)",
|
||||
"Bash(go generate *)",
|
||||
|
||||
"Bash(python *)",
|
||||
"Bash(python3 *)",
|
||||
"Bash(pytest *)",
|
||||
"Bash(pip install *)",
|
||||
"Bash(pip install -r *)",
|
||||
"Bash(uv *)",
|
||||
"Bash(ruff *)",
|
||||
"Bash(black *)",
|
||||
"Bash(mypy *)",
|
||||
"Bash(alembic *)",
|
||||
|
||||
"Bash(make)",
|
||||
"Bash(make *)",
|
||||
|
||||
"Bash(php *)",
|
||||
"Bash(composer *)",
|
||||
"Bash(wp *)",
|
||||
|
||||
"Bash(flutter *)",
|
||||
"Bash(dart *)",
|
||||
|
||||
"Bash(docker build *)",
|
||||
"Bash(docker ps*)",
|
||||
"Bash(docker images*)",
|
||||
"Bash(docker logs *)",
|
||||
"Bash(docker stop *)",
|
||||
"Bash(docker rm *)",
|
||||
|
||||
"Bash(node *)",
|
||||
"Bash(ts-node *)",
|
||||
"Bash(tsx *)",
|
||||
"Bash(npx *)",
|
||||
|
||||
"Bash(norminette*)"
|
||||
],
|
||||
|
||||
"ask": [
|
||||
|
||||
"Bash(make deploy*)",
|
||||
"Bash(npm run deploy*)",
|
||||
"Bash(cargo publish*)",
|
||||
|
||||
"Bash(psql *)",
|
||||
"Bash(mysql *)",
|
||||
"Bash(mongosh *)",
|
||||
"Bash(redis-cli *)"
|
||||
],
|
||||
|
||||
"deny": []
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,32 @@
|
||||
{
|
||||
"_readme": "Personal local overrides — DO NOT commit. Add .claude/settings.local.json to .gitignore. Highest priority after CLI flags.",
|
||||
|
||||
"permissions": {
|
||||
|
||||
"defaultMode": "default",
|
||||
|
||||
"allow": [
|
||||
|
||||
"WebFetch(domain:docs.anthropic.com)",
|
||||
"WebFetch(domain:developer.mozilla.org)",
|
||||
"WebFetch(domain:docs.rs)",
|
||||
"WebFetch(domain:pkg.go.dev)",
|
||||
"WebFetch(domain:pypi.org)",
|
||||
"WebFetch(domain:npmjs.com)",
|
||||
"WebFetch(domain:crates.io)",
|
||||
"WebFetch(domain:docs.python.org)",
|
||||
"WebFetch(domain:react.dev)",
|
||||
"WebFetch(domain:nextjs.org)",
|
||||
"WebFetch(domain:vuejs.org)",
|
||||
"WebFetch(domain:laravel.com)",
|
||||
"WebFetch(domain:flutter.dev)"
|
||||
],
|
||||
|
||||
"deny": [],
|
||||
|
||||
"ask": [],
|
||||
|
||||
"additionalDirectories": [
|
||||
]
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user