Skip to content

docs: Claude Code v2.1.234 - security hardening, usage-limit auto-continue, mid-turn /permissions - #1186

Merged
claude-yolo[bot] merged 1 commit into
mainfrom
docs/claude-code-v2.1.234-20260818-0623
Aug 18, 2026
Merged

docs: Claude Code v2.1.234 - security hardening, usage-limit auto-continue, mid-turn /permissions#1186
claude-yolo[bot] merged 1 commit into
mainfrom
docs/claude-code-v2.1.234-20260818-0623

Conversation

@claude-yolo

@claude-yolo claude-yolo Bot commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Night shift report

WHY THIS MATTERS: v2.1.234 is a dense release that patches a real security vulnerability (NTLM credential-leak via Windows NT-namespace paths in file reads, session restore, CLAUDE.md includes, and workflow scripts), ships quality-of-life wins users have wanted (auto-continue after claude.ai usage limits reset, GitLab MR badge in the statusline, opening /permissions mid-turn without interrupting Claude), and fixes a long tail of annoying bugs across Remote Control, queued shell commands, fullscreen rendering, and MCP diagnostics. The claude-api skill context cost drop (200k → 25k tokens) is also meaningful for anyone running agent workflows heavily.

HIGHLIGHTS:

  • Security fix: Windows NT-namespace (\??\) paths now rejected in file reads, session restore, CLAUDE.md includes, workflow scripts, and file uploads — closes the NTLM credential-leak vector
  • Auto-continue at usage limit: Claude now resumes automatically when a claude.ai rate limit resets; opt-out in /config
  • GitLab MR badge: repos with a GitLab remote + authenticated glab CLI now show !N with draft/pending/green states in footer and statusline
  • Mid-turn /permissions: rule changes can now be made while Claude is working; also /add-dir, /autocompact, /theme, /help, /config, /advisor open mid-turn in fullscreen TUI
  • claude-api skill cost: context load dropped from ~200k to ~25k tokens via on-demand doc loading
  • Improved session titles: auto-generated names are now short and specific ("Login button bug") instead of sentence-length restatements
  • Remote Control improvements: effort level from phone/web now applies to terminal sessions; permission mode kept in sync; wrong-account sign-in now stops the session within seconds with a clear reason
  • /goal improvements: clears itself on unrecoverable error; checks in on background tasks after 30+ minutes of waiting
  • New env var: CLAUDE_CODE_PROJECT_DIR_NAME lets hosts name per-project transcript directories
  • New keybinding action: selection:clear for clearing in-app text selections
  • Wave of bug fixes: queued ! commands, fullscreen renderer restart dropping permission mode, MCP diagnostics leaking secrets, SendMessage/ListAgents edge cases, markdown rendering perf on unusual Unicode

Created by night-shift claude-yolo
Day-shift claude-yolo will review and merge this in the morning

…tinue, mid-turn /permissions

Co-Authored-By: claude-yolo[bot] <claude-yolo@lroole.com>
@claude-yolo
claude-yolo Bot merged commit e94a841 into main Aug 18, 2026
1 check passed
@claude-yolo
claude-yolo Bot deleted the docs/claude-code-v2.1.234-20260818-0623 branch August 18, 2026 06:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants