Repository navigation
Permissions ignored #16331
Description
Activity
- addedcoreAnything pertaining to core functionality of the application (opencode server stuff)Anything pertaining to core functionality of the application (opencode server stuff)
on Mar 6, 2026 This issue might be a duplicate of existing issues. Please check:
- Path-based read permissions not enforced; catch-all rules always take precedence #13646: Path-based read permissions not enforced; catch-all rules always take precedence (very similar - specific file patterns in read permissions being ignored)
- Permissions are no longer working after 6 to 8 weeks as is #15754: Permissions are no longer working after 6 to 8 weeks as is (related - permissions not being respected generally)
If your issue is distinct from these, please add a comment explaining how it differs.
@MonsieurTib Was able to reproduce the issue, a solution would be to use this
"read": { "*.env": "deny", "*.env.*": "deny", "**/appsettings.json": "deny", "**/appsettings.*.json": "deny", "**/secrets.json": "deny", },
I omitted the
"*"permission, because that is already added in opencode by default.Try this and let me know how it works for you
I will try this approach later, but I’m not sure it will reassure the security team, since OpenCode explicitly states that it does not have the permission (so it wasn’t a configuration issue) but then proceeds anyway.
@avramukk ill check this out too
@avramukk I am not able to reproduce the issue you have, using your exact config I always get asked before curl is run as set
@avramukk I am not able to reproduce the issue you have, using your exact config I always get asked before curl is run as set
hmmm, which version? (my is 1.2.20)
hmmm, which version? (my is 1.2.20)
1.2.20
@MonsieurTib I found it. The problem is MCP. Try to remove it from the config, and it will ask for permissions again
@avramukk This is not a solution, and it doesn’t appear to be a configuration issue since the permission denial was correctly detected but then ignored ( cf the screenshot I shared )
@MonsieurTib I found it. The problem is MCP. Try to remove it from the config, and it will ask for permissions again
What MCPs are you using that prevents permissions from being enforced?
@MonsieurTib I found it. The problem is MCP. Try to remove it from the config, and it will ask for permissions again
What MCPs are you using that prevents permissions from being enforced?
Sorry, it was a cursor plugin
"@rama_nigg/open-cursor@latest"20 remaining items
@Nindaleth The tools block is deprecated but can still be used we are just encouraging use of permissions, when you make use of the tools block the way you are it works, permissions are mostly meant for built in tools and even custom user tools, but for mcps, I am not too sure you can restrict them directly for example restricting only
gitcommands for bash. So having an mcp in a tool block as true just means its enabled, and as false as disabled.tools: mcp-atlassian_*: true
should be the same as
permissions: mcp-atlassian_*: allow
and
tools: mcp-atlassian_*: false
should be the same as
permissions: mcp-atlassian_*: deny
Reacted by Nindaleth@jhutchings1 could you please use the
/sharecommand and share the link here, of you doing another test@jhutchings1 could you please use the
/sharecommand and share the link here, of you doing another test@OpeOginni our share links are all behind a corporate SSO config, so the share wouldn't work, unfortunately.
@RisaKirisu Plan mode is generally made to NOT edit files, so please make use of another agent than plan mode and add these permissions. Using the build agent and your config I was able to edit that file.
@OpeOginni Thanks for the follow up testing. However, I'm still not observing the same behavior as you. I'm on 1.2.27 now. I have reduced the config file to isolate out the permission system, and applied the settings on build agent only to test, yet the same problem still occur:
{ "$schema": "https://opencode.ai/config.json", "agent": { "build": { "model": "openrouter/google/gemini-3.1-pro-preview-customtools", "tools": { "lsp": true }, "permission": { "edit": { "*": "deny", ".agents/*": "allow", ".agents/*.md": "allow" }, "lsp": "allow" } } }, "small_model": "openrouter/openai/gpt-oss-120b:exacto" }
https://opncd.ai/share/Qt3mDZLB
If I change the permission on edit
*toask, the permission behavior for editing.agents/test.mdin practice also become ask.@RisaKirisu do you have a git repo initialised on this project?
@OpeOginni No. I just tested again after running
git initin the test dir, and the permission started working expectedly. So it seems the permission system isn't working as intended when the directory isn't a git repo, but works correctly otherwise.Yeah noticed that as well so since
It's the same with you I can go ahead with a fix for it, should have one out by Monday or if someone else would be faster@RisaKirisu made a PR that should fix this issue, hopefully it gets merged in
Reacted by graelo and RisaK- removedbugSomething isn't workingSomething isn't workingcoreAnything pertaining to core functionality of the application (opencode server stuff)Anything pertaining to core functionality of the application (opencode server stuff)
on May 3, 2026 This issue seems to still happen even on v1.15.13 of Opencode Desktop on Windows. Neither the read tool nor any other tool prompt for permission when trying to for example access a directory outside of the Working directory while the config for permission says it needs to ask before doing so.
Hope this gets fixed soon as currently opencode can just extract API keys and more from external directories which it should never be able to do. It can also just access other workspaces from it's current one and possibly expose/break stuff there.
Here's my extensive (redacted) config for easy checking btw:
{ "$schema": "https://opencode.ai/config.json", "disabled_providers": [], "provider": { "cf_ai": { "name": "CF AI", "npm": "@ai-sdk/openai-compatible", "options": { "baseURL": "https://api.cloudflare.com/client/v4/accounts/ACCOUNT_ID_REDACTED/ai/v1" }, "models": { "@cf/moonshotai/kimi-k2.5": { "name": "kimi-k2.5", "reasoning": true, "limit": { "context": 256000, "output": 4096 }, "modalities": { "input": ["text", "image", "video"], "output": ["text"] } }, "@cf/moonshotai/kimi-k2.6": { "name": "kimi-k2.6", "reasoning": true, "limit": { "context": 262144, "output": 4096 }, "modalities": { "input": ["text", "image", "video"], "output": ["text"] } } } } }, "permission": { "*": "allow", "read": { "*.env": "deny, "*.env.*": "deny", "**/appsettings.json": "deny", "**/appsettings.*.json": "deny", "**/secrets.json": "deny", }, "bash": { "*": "allow", "touch *": "ask", "mkdir *": "ask", "rm *": "ask", "cp *": "ask", "mv *": "ask", "dd *": "ask", "sudo *": "ask", "chmod *": "ask", "chown *": "ask", "curl *": "ask", "wget *": "ask", "npm install *": "ask", "pip install *": "ask", "git push": "ask", "git reset --hard *": "ask", "git clean *": "ask", "reboot": "ask", "shutdown": "ask", "kill *": "ask", "killall *": "ask", "docker *": "ask", "mkfs *": "ask", "fdisk *": "ask", "parted *": "ask", "format *": "ask", "git branch -d *": "ask", "git branch -D *": "ask", "git rebase *": "ask", "npm run publish": "ask", "brew install *": "ask", "brew upgrade *": "ask", "ssh *": "ask", "scp *": "ask", "rsync *": "ask" }, "doom_loop": "ask", "external_directory": "ask" }, "mcp": { "exa": { "type": "remote", "url": "https://mcp.exa.ai/mcp", "enabled": true, "headers": { "Authorization": "Bearer ${EXA_API_KEY}" } } } }To stay organized issues are automatically closed after 60 days of no activity. If the issue is still relevant please open a new one.
Reacted by Tsung-Han Yu, Nathan Greene, Momchil Georgiev and SlothrupReacted by Jakob Klepp and Nathan Greene

Description
I have the following opencode.json configuration
and asked Opencode to validate the format of the .env and appsettings.json files in my project.
Opencode correctly detects that it does not have permission to read the .env file and does not access it. However, for appsettings.json, it reports that it does not have permission but then proceeds to read the file anyway.
Plugins
No response
OpenCode version
1.2.20
Steps to reproduce
No response
Screenshot and/or share link
Operating System
macOS Tahoe 26.3
Terminal
Ghostty