feat(dis): flag ineffective allow wildcards; treat Tool(*) as deny-all
Extends the DIS scanner and its shared permission-rules lib with two
documented Claude Code permission footguns. Verified verbatim against
code.claude.com/docs/en/permissions (fetched 2026-06-19).
- lib/permission-rules.mjs: new isIneffectiveAllowGlob(entry) — unanchored
tool-name globs in permissions.allow (`*`, `B*`, `mcp__*`) that CC silently
skips ("does not auto-approve anything"); valid only as a glob-free
`mcp__<server>__*`. Shared with CNF.
- lib/permission-rules.mjs: dominates() now treats the `Tool(*)` deny-all glob
as equivalent to a bare deny (covers a bare allow) — CC: "Bash(*) is
equivalent to Bash ... both forms remove the tool from Claude's context".
- DIS: new finding "Ineffective allow wildcard — Claude Code ignores this rule"
(low, permissions-hygiene, CA-DIS-NNN); the existing dead-allow finding now
also catches a bare allow killed by a Tool(*) deny.
- 9 new tests (5 lib, 4 DIS) + 2 fixtures (force-added past .gitignore .claude/).
Suite 903 -> 912. Snapshot unchanged, contamination grep clean. README/CLAUDE/
scanner-internals document the broadened DIS mandate; test badge synced.
self-audit: PASS, configGrade A 96, pluginGrade A 100, readme gate passed.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ter3E2JSi1Khgmuf2kady8
This commit is contained in:
parent
dfe9049b55
commit
03949c6c98
9 changed files with 198 additions and 28 deletions
6
tests/fixtures/deny-all-glob/.claude/settings.json
vendored
Normal file
6
tests/fixtures/deny-all-glob/.claude/settings.json
vendored
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
{
|
||||
"permissions": {
|
||||
"allow": ["Bash"],
|
||||
"deny": ["Bash(*)"]
|
||||
}
|
||||
}
|
||||
5
tests/fixtures/ineffective-allow-globs/.claude/settings.json
vendored
Normal file
5
tests/fixtures/ineffective-allow-globs/.claude/settings.json
vendored
Normal file
|
|
@ -0,0 +1,5 @@
|
|||
{
|
||||
"permissions": {
|
||||
"allow": ["mcp__*", "B*", "mcp__puppeteer__*", "Bash(npm run *)", "Read"]
|
||||
}
|
||||
}
|
||||
|
|
@ -5,6 +5,7 @@ import {
|
|||
paramMatches,
|
||||
dominates,
|
||||
rulesIntersect,
|
||||
isIneffectiveAllowGlob,
|
||||
} from '../../scanners/lib/permission-rules.mjs';
|
||||
|
||||
describe('permission-rules — parseRule', () => {
|
||||
|
|
@ -70,11 +71,44 @@ describe('permission-rules — dominates (deny fully covers allow → dead allow
|
|||
assert.equal(dominates('Agent(model:opus)', 'Agent'), false);
|
||||
});
|
||||
|
||||
it('deny-all glob Tool(*) covers a bare allow (Bash(*) ≡ bare Bash deny)', () => {
|
||||
// CC: "Bash(*) is equivalent to Bash ... As a deny rule, both forms remove
|
||||
// the tool from Claude's context." So Bash(*) deny kills a bare Bash allow.
|
||||
assert.equal(dominates('Bash(*)', 'Bash'), true);
|
||||
assert.equal(dominates('Bash(*)', 'Bash(npm:*)'), true);
|
||||
});
|
||||
|
||||
it('different tools never dominate', () => {
|
||||
assert.equal(dominates('Bash', 'Read'), false);
|
||||
});
|
||||
});
|
||||
|
||||
describe('permission-rules — isIneffectiveAllowGlob (CC silently skips these allow entries)', () => {
|
||||
it('unanchored tool-name globs are ineffective', () => {
|
||||
assert.equal(isIneffectiveAllowGlob('*'), true);
|
||||
assert.equal(isIneffectiveAllowGlob('B*'), true);
|
||||
assert.equal(isIneffectiveAllowGlob('mcp__*'), true);
|
||||
assert.equal(isIneffectiveAllowGlob('mcp__*__foo'), true); // glob in server segment
|
||||
});
|
||||
|
||||
it('MCP globs anchored to a literal server are valid (not flagged)', () => {
|
||||
assert.equal(isIneffectiveAllowGlob('mcp__puppeteer__*'), false);
|
||||
assert.equal(isIneffectiveAllowGlob('mcp__github__get_*'), false);
|
||||
});
|
||||
|
||||
it('non-glob and specifier forms are valid (not flagged)', () => {
|
||||
assert.equal(isIneffectiveAllowGlob('Bash'), false); // legit match-all-tool allow
|
||||
assert.equal(isIneffectiveAllowGlob('mcp__puppeteer'), false); // legit match-all-server
|
||||
assert.equal(isIneffectiveAllowGlob('Bash(npm run *)'), false);// glob inside specifier is fine
|
||||
assert.equal(isIneffectiveAllowGlob('Read(src/**)'), false);
|
||||
});
|
||||
|
||||
it('non-string → false', () => {
|
||||
assert.equal(isIneffectiveAllowGlob(null), false);
|
||||
assert.equal(isIneffectiveAllowGlob(undefined), false);
|
||||
});
|
||||
});
|
||||
|
||||
describe('permission-rules — rulesIntersect (cross-scope conflict)', () => {
|
||||
it('exact same rule intersects', () => {
|
||||
assert.equal(rulesIntersect('Bash(npm run *)', 'Bash(npm run *)'), true);
|
||||
|
|
|
|||
|
|
@ -95,3 +95,44 @@ describe('DIS scanner — param-qualified permissions are param-aware', () => {
|
|||
assert.doesNotMatch(String(f?.evidence || ''), /WebFetch/);
|
||||
});
|
||||
});
|
||||
|
||||
describe('DIS scanner — ineffective allow wildcards (CC skips unanchored tool-name globs)', () => {
|
||||
// settings.json allow: ["mcp__*", "B*", "mcp__puppeteer__*", "Bash(npm run *)", "Read"]
|
||||
// CC skips `mcp__*` and `B*` (unanchored tool-name globs) — dead config.
|
||||
// `mcp__puppeteer__*` (anchored), `Bash(npm run *)` (specifier glob) and `Read` are valid.
|
||||
|
||||
it('flags the ineffective allow globs with low severity', async () => {
|
||||
const result = await runScanner('ineffective-allow-globs');
|
||||
const f = result.findings.find(x => /ineffective allow wildcard/i.test(x.title || ''));
|
||||
assert.ok(f, `expected ineffective-allow-glob finding; got: ${result.findings.map(x => x.title).join(' | ')}`);
|
||||
assert.equal(f.severity, 'low', `expected low, got ${f.severity}`);
|
||||
assert.match(f.id, /^CA-DIS-\d{3}$/);
|
||||
});
|
||||
|
||||
it('evidence cites only the unanchored globs, not the valid entries', async () => {
|
||||
const result = await runScanner('ineffective-allow-globs');
|
||||
const f = result.findings.find(x => /ineffective allow wildcard/i.test(x.title || ''));
|
||||
assert.ok(f);
|
||||
assert.match(String(f.evidence || ''), /mcp__\*/);
|
||||
assert.match(String(f.evidence || ''), /B\*/);
|
||||
assert.doesNotMatch(String(f.evidence || ''), /puppeteer/); // anchored MCP glob is valid
|
||||
assert.doesNotMatch(String(f.evidence || ''), /npm run/); // specifier glob is valid
|
||||
});
|
||||
|
||||
it('clean settings (no unanchored globs) → no ineffective-allow finding', async () => {
|
||||
const result = await runScanner('healthy-project');
|
||||
const f = result.findings.find(x => /ineffective allow wildcard/i.test(x.title || ''));
|
||||
assert.equal(f, undefined, `expected no ineffective-allow finding; got: ${f?.title}`);
|
||||
});
|
||||
});
|
||||
|
||||
describe('DIS scanner — deny-all glob Tool(*) kills a bare allow (end-to-end)', () => {
|
||||
// settings.json: allow: ["Bash"], deny: ["Bash(*)"]
|
||||
// Bash(*) deny ≡ bare Bash deny → the bare Bash allow is dead config.
|
||||
it('flags the bare Bash allow as dead under a Bash(*) deny', async () => {
|
||||
const result = await runScanner('deny-all-glob');
|
||||
const f = result.findings.find(x => /both permissions\.deny and permissions\.allow/i.test(x.title || ''));
|
||||
assert.ok(f, `expected the bare Bash allow to be flagged dead; got: ${result.findings.map(x => x.title).join(' | ')}`);
|
||||
assert.match(String(f.evidence || ''), /Bash/);
|
||||
});
|
||||
});
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue