Skip to content
claudewheel.permission
Edit
On this page

Core logic for managing profile permission rules.

#claudewheel.permission

#claudewheel.permission

Core logic for managing profile permission rules.

#validate_rule

python
def validate_rule(rule: str) -> None

Raise ValueError if rule is not a valid permission rule string.

Rules are either bare tool names (Bash) or tool-with-pattern (Bash(git diff:*)). Empty, whitespace-only, and malformed strings are rejected.

#load_settings

python
def load_settings(settings_path: Path) -> dict[str, Any]

Read and parse a profile's settings.json.

Raises FileNotFoundError if the file does not exist and json.JSONDecodeError if the content is not valid JSON.

#save_settings

python
def save_settings(settings_path: Path, data: dict[str, Any]) -> None

Atomic-write data as JSON to settings_path.

Writes to a uniquely named staging file in the target's own directory first, then commits it with os.replace to avoid partial writes, preserving the file's mode.

#add_rule

python
def add_rule(data: dict[str, Any], category: str, rule: str) -> str

Append rule to data["permissions"][category].

Returns "added" on success or "already present" if the rule already exists in the list. The list is never sorted -- append only.

#remove_rule

python
def remove_rule(data: dict[str, Any], category: str, rule: str) -> str

Remove rule from data["permissions"][category].

Returns "removed" on success or "not found" if the rule is not in the list.

#resolve_profiles

python
def resolve_profiles(ws: 'Workspace', profile: str | None, all_profiles: bool) -> list[tuple[str, Path]]

Map the mutex flag values to a list of (name, settings_path) pairs.

"No target chosen" is refused rather than read as "every profile". The mutex group does not guarantee a choice arrives here: strictcli elects a string member on PRESENCE with any value, so --profile '' satisfies the group, and the CLI handlers normalize that empty string to None before calling. Both sides then arrive false with the parser satisfied. (The other spelling is gone: since strictcli 0.40.0 a present-but-false negatable boolean no longer elects, so --no-all-profiles is refused at parse time.)

Prints to stderr and exits on error. Enumeration uses the workspace's ProfileStore, so a corrupt token entry raises TokenStoreError -- the uniform hard-error contract; permission commands are settings.json operations, but an unreadable token entry is a workspace-integrity problem the operator must fix.

More tools from this site

  • claudestream Drive Claude Code from Python: run it as a subprocess and read its output as typed events, with async and sync sessions, sandbox policies, and tools you define in Python
  • dirstat Fast, single-binary directory statistics CLI: every file under a tree grouped by format, with counts, sizes, and lines of code, as a colored terminal table or as JSON
  • fastware A batteries-included ASGI framework: msgspec JSON, a managed Granian server, dependency injection, SSE, WebSockets, auth, and a test client
  • go-toml-edit Zero-dep TOML editing library for Go with comment preservation
  • howmuchleft The fastest Claude Code statusline: context window, 5-hour, and weekly limit usage as three customizable gradient bars, rendering in about 6 ms
  • orxtra
  • pgdesign
  • predraw Declarative rendering pipeline: describe a scene in JSON and get SVG, PNG and WebP out, with light and dark style tokens, reusable components and text converted to path outlines
  • reposummary Turn a git repository's history into a Markdown journal: pick a time window or revision range and get a readable digest of what changed, optionally narrated by an LLM
  • rlsbl Release orchestration and project scaffolding CLI that bumps versions, validates a structured JSONL changelog, tags only the commit CI verified, and publishes to npm, PyPI, Go and more
  • safegit git wrapper CLI that gives each commit its own temporary index and retries ref updates on conflict, so concurrent agents share one repository
  • saferm Command-line replacement for rm that archives every deletion with a mandatory reason and the context it ran in, so deleted files can be listed, inspected and restored
  • selfdoc Static Site Generator that builds a project's documentation site directly from its source code, so the docs can never drift from the code they describe, with SEO/AEO, first-class blog, search, and cross-project linking built in
  • strictcli
  • stricttest An always-on test-isolation floor: a pytest plugin and a Go env-hygiene module that make a test suite structurally unable to reach real credentials, the real HOME, the network, or the development repository.
  • wesktop A Python framework that turns an ASGI web app into a desktop application, serving it from a local Granian server and displaying it in a native OS window via pywebview
Search