"""PreToolUse hook for Edit|Write: block edits to generated output and production config.

Exit code 2 blocks the tool call, and Claude Code passes stderr to Claude as the reason,
so each message says what to do instead.
"""

import json
import posixpath
import sys

# A path segment to protect, and what Claude should do instead.
PROTECTED = {
    "/generated/": "Files here are written by the build. Change the source and rerun the build.",
    "/config/prod/": "This is production configuration. Describe the change in your reply; "
    "a person makes it through a reviewed pull request.",
}


def normalise(path: str) -> str:
    """Forward slashes, '..' resolved, with a leading and trailing slash for segment matching."""
    return posixpath.normpath(path.replace("\\", "/")).rstrip("/") + "/"


def main() -> int:
    event = json.load(sys.stdin)
    path = normalise(event.get("tool_input", {}).get("file_path", ""))
    for segment, advice in PROTECTED.items():
        if segment in path:
            print(f"Blocked: {path.rstrip('/')} is protected. {advice}", file=sys.stderr)
            return 2
    return 0


if __name__ == "__main__":
    sys.exit(main())
