Skip to content

Permissions ignored #16331

Description

@MonsieurTib

Description

I have the following opencode.json configuration

  "$schema": "https://opencode.ai/config.json",
  "permission": {
    "external_directory": "ask",
    "read": {
      "*": "allow",
      "*.env": "deny",
      "*.env.*": "deny",
      "appsettings.json": "deny",
      "appsettings.*.json": "deny",
      "secrets.json": "deny"
    },
    "bash": {
      "*": "allow",
      "git *": "ask",
      "gh *": "ask",
      "az *": "ask",
      "rm -rf *": "deny",
      "dotnet user-secrets *": "deny",
      "docker *": "ask",
      "curl *": "ask"
    },
  },
  "mcp": {
    "context7": {
      "type": "remote",
      "url": "https://mcp.context7.com/mcp",
      "enabled": true
    },
    "grep_app": {
      "type": "remote",
      "url": "https://mcp.grep.app",
      "enabled": true
    }
  }
}

and asked Opencode to validate the format of the .env and appsettings.json files in my project.
Opencode correctly detects that it does not have permission to read the .env file and does not access it. However, for appsettings.json, it reports that it does not have permission but then proceeds to read the file anyway.

Plugins

No response

OpenCode version

1.2.20

Steps to reproduce

No response

Screenshot and/or share link

Image

Operating System

macOS Tahoe 26.3

Terminal

Ghostty

Activity

  1. added
    coreAnything pertaining to core functionality of the application (opencode server stuff)
    on Mar 6, 2026
  2. github-actions commented on Mar 6, 2026

    @github-actions
    Contributor

    This issue might be a duplicate of existing issues. Please check:

    If your issue is distinct from these, please add a comment explaining how it differs.

  3. OpeOginni commented on Mar 6, 2026

    @OpeOginni
    Contributor

    @MonsieurTib Was able to reproduce the issue, a solution would be to use this

      "read": {
        "*.env": "deny",
        "*.env.*": "deny",
        "**/appsettings.json": "deny",
        "**/appsettings.*.json": "deny",
        "**/secrets.json": "deny",
      },

    I omitted the "*" permission, because that is already added in opencode by default.

    Try this and let me know how it works for you

  4. MonsieurTib commented on Mar 6, 2026

    @MonsieurTib
    Author

    I will try this approach later, but I’m not sure it will reassure the security team, since OpenCode explicitly states that it does not have the permission (so it wasn’t a configuration issue) but then proceeds anyway.

  5. avramukk commented on Mar 6, 2026

    @avramukk

    Same for me. All permissions are ignored.
    And all commands running much longer than before (41 s for curl?)
    Also, I don't understand why the context always starting form 70000 input tokens? Any way to debug it? I have almost nothing in config and agents.md.
    Image

  6. OpeOginni commented on Mar 6, 2026

    @OpeOginni
    Contributor

    @avramukk ill check this out too

  7. OpeOginni commented on Mar 6, 2026

    @OpeOginni
    Contributor

    @avramukk I am not able to reproduce the issue you have, using your exact config I always get asked before curl is run as set

  8. avramukk commented on Mar 6, 2026

    @avramukk

    @avramukk I am not able to reproduce the issue you have, using your exact config I always get asked before curl is run as set

    hmmm, which version? (my is 1.2.20)

  9. OpeOginni commented on Mar 6, 2026

    @OpeOginni
    Contributor

    hmmm, which version? (my is 1.2.20)

    1.2.20

  10. avramukk commented on Mar 6, 2026

    @avramukk

    @MonsieurTib I found it. The problem is MCP. Try to remove it from the config, and it will ask for permissions again

  11. MonsieurTib commented on Mar 6, 2026

    @MonsieurTib
    Author

    @avramukk This is not a solution, and it doesn’t appear to be a configuration issue since the permission denial was correctly detected but then ignored ( cf the screenshot I shared )

  12. OpeOginni commented on Mar 6, 2026

    @OpeOginni
    Contributor

    @MonsieurTib I found it. The problem is MCP. Try to remove it from the config, and it will ask for permissions again

    What MCPs are you using that prevents permissions from being enforced?

  13. avramukk commented on Mar 6, 2026

    @avramukk

    @MonsieurTib I found it. The problem is MCP. Try to remove it from the config, and it will ask for permissions again

    What MCPs are you using that prevents permissions from being enforced?

    Sorry, it was a cursor plugin
    "@rama_nigg/open-cursor@latest"

  14. 20 remaining items

  15. OpeOginni commented on Mar 19, 2026

    @OpeOginni
    Contributor

    @Nindaleth The tools block is deprecated but can still be used we are just encouraging use of permissions, when you make use of the tools block the way you are it works, permissions are mostly meant for built in tools and even custom user tools, but for mcps, I am not too sure you can restrict them directly for example restricting only git commands for bash. So having an mcp in a tool block as true just means its enabled, and as false as disabled.

    tools:
      mcp-atlassian_*: true

    should be the same as

    permissions:
      mcp-atlassian_*: allow

    and

    tools:
      mcp-atlassian_*: false

    should be the same as

    permissions:
      mcp-atlassian_*: deny
  16. OpeOginni commented on Mar 19, 2026

    @OpeOginni
    Contributor

    @jhutchings1 could you please use the /share command and share the link here, of you doing another test

  17. jhutchings1 commented on Mar 19, 2026

    @jhutchings1

    @jhutchings1 could you please use the /share command and share the link here, of you doing another test

    @OpeOginni our share links are all behind a corporate SSO config, so the share wouldn't work, unfortunately.

  18. RisaKirisu commented on Mar 20, 2026

    @RisaKirisu

    @RisaKirisu Plan mode is generally made to NOT edit files, so please make use of another agent than plan mode and add these permissions. Using the build agent and your config I was able to edit that file.

    @OpeOginni Thanks for the follow up testing. However, I'm still not observing the same behavior as you. I'm on 1.2.27 now. I have reduced the config file to isolate out the permission system, and applied the settings on build agent only to test, yet the same problem still occur:

    {
      "$schema": "https://opencode.ai/config.json",
      "agent": {
        "build": {
          "model": "openrouter/google/gemini-3.1-pro-preview-customtools",
          "tools": {
            "lsp": true
          },
          "permission": {
            "edit": {
              "*": "deny",
              ".agents/*": "allow",
              ".agents/*.md": "allow"
            },
            "lsp": "allow"
          }
        }
      },
      "small_model": "openrouter/openai/gpt-oss-120b:exacto"
    }
    Image https://opncd.ai/share/Qt3mDZLB

    If I change the permission on edit * to ask, the permission behavior for editing .agents/test.md in practice also become ask.

  19. OpeOginni commented on Mar 21, 2026

    @OpeOginni
    Contributor

    @RisaKirisu do you have a git repo initialised on this project?

  20. RisaKirisu commented on Mar 22, 2026

    @RisaKirisu

    @OpeOginni No. I just tested again after running git init in the test dir, and the permission started working expectedly. So it seems the permission system isn't working as intended when the directory isn't a git repo, but works correctly otherwise.

  21. OpeOginni commented on Mar 22, 2026

    @OpeOginni
    Contributor

    Yeah noticed that as well so since
    It's the same with you I can go ahead with a fix for it, should have one out by Monday or if someone else would be faster

  22. OpeOginni commented on Mar 23, 2026

    @OpeOginni
    Contributor

    @RisaKirisu made a PR that should fix this issue, hopefully it gets merged in

  23. assigned and unassigned on Apr 26, 2026
  24. removed
    bugSomething isn't working
    coreAnything pertaining to core functionality of the application (opencode server stuff)
    on May 3, 2026
  25. Chaoskjell44 commented on Jun 1, 2026

    @Chaoskjell44

    This issue seems to still happen even on v1.15.13 of Opencode Desktop on Windows. Neither the read tool nor any other tool prompt for permission when trying to for example access a directory outside of the Working directory while the config for permission says it needs to ask before doing so.

    Hope this gets fixed soon as currently opencode can just extract API keys and more from external directories which it should never be able to do. It can also just access other workspaces from it's current one and possibly expose/break stuff there.

    Here's my extensive (redacted) config for easy checking btw:

    {
      "$schema": "https://opencode.ai/config.json",
      "disabled_providers": [],
      "provider": {
        "cf_ai": {
          "name": "CF AI",
          "npm": "@ai-sdk/openai-compatible",
          "options": {
            "baseURL": "https://api.cloudflare.com/client/v4/accounts/ACCOUNT_ID_REDACTED/ai/v1"
          },
          "models": {
            "@cf/moonshotai/kimi-k2.5": {
              "name": "kimi-k2.5",
              "reasoning": true,
              "limit": {
                "context": 256000,
                "output": 4096
              },
              "modalities": {
                "input": ["text", "image", "video"],
                "output": ["text"]
              }
            },
            "@cf/moonshotai/kimi-k2.6": {
              "name": "kimi-k2.6",
              "reasoning": true,
              "limit": {
                "context": 262144,
                "output": 4096
              },
              "modalities": {
                "input": ["text", "image", "video"],
                "output": ["text"]
              }
            }
          }
        }
      },
      "permission": {
        "*": "allow",
        "read": {
          "*.env": "deny,
          "*.env.*": "deny",
          "**/appsettings.json": "deny",
          "**/appsettings.*.json": "deny",
          "**/secrets.json": "deny",
        },
        "bash": {
          "*": "allow",
          "touch *": "ask",
          "mkdir *": "ask",
          "rm *": "ask",
          "cp *": "ask",
          "mv *": "ask",
          "dd *": "ask",
          "sudo *": "ask",
          "chmod *": "ask",
          "chown *": "ask",
          "curl *": "ask",
          "wget *": "ask",
          "npm install *": "ask",
          "pip install *": "ask",
          "git push": "ask",
          "git reset --hard *": "ask",
          "git clean *": "ask",
          "reboot": "ask",
          "shutdown": "ask",
          "kill *": "ask",
          "killall *": "ask",
          "docker *": "ask",
          "mkfs *": "ask",
          "fdisk *": "ask",
          "parted *": "ask",
          "format *": "ask",
          "git branch -d *": "ask",
          "git branch -D *": "ask",
          "git rebase *": "ask",
          "npm run publish": "ask",
          "brew install *": "ask",
          "brew upgrade *": "ask",
          "ssh *": "ask",
          "scp *": "ask",
          "rsync *": "ask"
        },
        "doom_loop": "ask",
        "external_directory": "ask"
      },
      "mcp": {
        "exa": {
          "type": "remote",
          "url": "https://mcp.exa.ai/mcp",
          "enabled": true,
          "headers": {
            "Authorization": "Bearer ${EXA_API_KEY}"
          }
        }
      }
    }
    
  26. github-actions commented on Aug 1, 2026

    @github-actions
    Contributor

    To stay organized issues are automatically closed after 60 days of no activity. If the issue is still relevant please open a new one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions