Changelog
Version history for Claude Control Center. All releases are available on the GitHub Releases page.
Security
timingsafe_bcmp (Darwin) to eliminate token timing side-channels on the local HTTP server.429 Too Many Requests for excess, preventing local DoS flooding.ccc_token is written via POSIX open(O_CREAT | O_EXCL, 0600) — never world-readable, never has a window where it is empty.os.replace() — no more corruption window if the process dies mid-write.* wildcard rule when the primary input is unrecognized — prevents accidentally greenlighting all future invocations of a tool.Fixed
(sessionId, toolName, primaryInput) — approving echo hello never auto-approves a different command.rm -r now critical: recursive delete without -f (e.g. rm -r dir, rm -R dir, rm --recursive dir) is now correctly classified as critical, not medium.checkAndInstallHooks now runs the installer subprocess off the main thread using Process.terminationHandler — no more UI freeze during first-launch hook setup.ApprovalModal, SessionAllowList, and DynamicIslandController no longer use ! force-unwraps on optionals that can be nil at runtime.build_dmg.sh now correctly stamps the current version into Info.plist for any 3-part version string (was hardcoded to match 0.1.0 only).deny instead of hanging indefinitely.Tests
SessionAllowList (15 tests), RiskClassifier (46 tests), approval flow, and HTTP server auth.Fixed
Active when a session is running but no specific tool label is set — e.g. between tool calls when menuBarStatusText has cleared. Previously the pill would disappear even though Claude was still mid-session.DynamicIslandController now observes activeSession?.status in addition to menuBarStatusText. The pill stays visible for the full duration of a running session.isSessionRunning to hasStatus check in syncPanelSize(), so the wide-active strip no longer collapses during inter-tool-call pauses.New
⌘⇧I).⌘⇧I: toggle the expanded pill from any app.panel.frame.maxY == screen.frame.maxY at all times, matching the notch hardware position exactly.Changed
Stop hook).New
UserDefaults, editable in the Rules tab, take effect immediately.NSRegularExpression pattern matching. Risk level shown in every activity row and approval dialog.Fixed
New
PreToolUse hook intercepts every tool call; CCC shows an approval dialog for medium/high/critical-risk commands. 30-second auto-allow timeout.~/.claude/settings.json with all required hook entries. No terminal commands needed.NWListener-based server on localhost:40440 with no third-party dependencies.localhost:40440. No telemetry, analytics, or accounts.