File write recovery · evidence checked August 1, 2026

Repair the denied ClientAppSettings.json write.

Preserve the file and complete error, close Luczystrap and Roblox, restart Windows once, then classify the exact path. If the error remains, use one temporary-file test to distinguish a blocked parent folder from a locked or read-only target file.

Do not delete the entire Roblox or Luczystrap tree, reset AppData permissions recursively, disable antivirus, or restore an old FastFlag pack before the baseline saves and launches.

Recurring error. No published universal fix.

The official tracker contains seven issues with the exact title UnauthorizedAccess_IODenied_Path, ClientAppSettings.json. Six remain open; the one closed report has no comments or maintainer explanation. The cluster proves repeat demand for a repair guide, not one shared cause.

7Exact-title reports

November 2025 through June 2026

Issues #77, #84, #96, #122, #143, #168, and #214 carry the same generated exception title. Their short or empty bodies do not provide a reproducible fix. This procedure therefore tests the Windows boundary instead of assigning a cause from frequency.

#77Open · Nov 2025
#84Open · Dec 2025
#96Closed · Dec 2025
#122Open · Jan 2026
#143Open · Jan 2026
#168Open · Mar 2026
#214Open · Jun 2026
Evidence boundary: a separate detailed 1.4.9 log in issue #218 shows Luczystrap loading and saving its modifications copy. That confirms a current working path, but it does not prove that every ClientAppSettings report failed at that same path or operation.

The full path chooses the repair lane.

Select the fragment visible in your exception. This tool does not inspect your computer or upload a path; it only explains what each local location means.

Path contains
Luczystrap working copy

Repair the persistent modifications source before a deployed copy.

%LocalAppData%\Luczystrap\Modifications\ClientSettings\ClientAppSettings.json

A detailed 1.4.9 log shows FastFlagManager loading and saving this location. Back up this file, test its parent folder, and let Luczystrap rebuild here before touching a version directory.

Next evidenceRead-only state of this file plus a create/rename/delete test in its ClientSettings parent.
Do not copy a version-folder file over this source until you know which copy contains the settings you intend to keep.

Keep the only useful failure intact.

Do this before a restart, attribute change, rename, reinstall, or security decision. Store the backup outside every active Luczystrap and Roblox folder.

  1. 01
    Copy the complete exception

    Keep the type, message, HRESULT if shown, exact path, operation, stack trace, and timestamp—not only the filename.

  2. 02
    Copy the matching Luczystrap log

    Use the log whose timestamp covers the failed save or launch. Preserve the original before reproducing again.

  3. 03
    Back up ClientAppSettings.json when readable

    Copy it to a dated folder such as Documents\Luczystrap-backup-2026-08-01\. Do not edit the backup.

  4. 04
    Record the file's current state

    Screenshot Properties → General and Security, including Read-only, owner, inheritance, and the current user's entries.

Move from a clean process state to one narrow file repair.

Repeat the same Luczystrap save after each step and stop at the first changed result. Combining repairs destroys the comparison that identifies the failed boundary.

Close every writer and restart once

Exit Luczystrap and Roblox normally. Close editors, sync tools, and other bootstrappers that may touch the same file. Restart Windows, open only Luczystrap, and repeat one save.

If it now saves, stop. The result is consistent with temporary process overlap; no ACL or antivirus change is justified.

Confirm the complete failed path

Return to the preserved exception or log. Classify the path with the tool above. A modifications source, Luczystrap-managed version, and official Roblox version are separate objects even when all end in ClientAppSettings.json.

If the path is truncated, collect the log before changing any file with the same name.

Test the parent folder without touching the target

With Luczystrap and Roblox closed, create an empty file beside the target named luczystrap-write-test.tmp. Rename it once, then remove it. Do not perform the test in a different folder.

create → rename → remove: luczystrap-write-test.tmpAll three succeed: the parent accepts ordinary writes, so inspect the target file. Any step fails: stop and treat this as a parent-folder or security boundary.

Inspect a target-file-only failure

If the folder test passed, open the exact file's Properties. If Read-only is checked on the file, clear it for that file only and retry. If it is not read-only, use a normal restart first; advanced users can use Microsoft's Process Explorer search to identify a process holding the exact path and then close that application normally.

Microsoft Process Explorer documentation ↗

Do not force-close a handle, end random Windows services, or use the folder Read-only checkbox as an ACL reset.

Check for a matching security event

Open Windows Security → Virus & threat protection → Protection history, or the event history of your active third-party antivirus. Match the same executable, destination, action, and time. Microsoft says Protection history retains events for two weeks.

Open Microsoft's Protection history guide ↗

No matching event means there is no evidence for disabling protection, restoring quarantine, or adding an exclusion.

Isolate the old file only when the folder is writable

After a verified backup, close both applications and rename the original to ClientAppSettings.json.pre-repair. Open Luczystrap and save once so it can create a fresh JSON file. If rename fails, stop; do not bypass the failure with ownership commands.

A fresh file that saves and launches isolates old file state. If the same exception remains, restore the backup name and escalate with the collected evidence.

Restore settings in small groups

Keep the fresh file as the baseline. Restore only flags you still need and that appear on Roblox's current allowlist. Save, launch, and restart between small groups. Keep the old backup until the full verification board passes.

Finish line: Luczystrap saves, Roblox launches, JSON remains valid, the timestamp changes, and the result survives one restart.
Folder test passes

Create, rename, and remove all work.

Inspect target file

Read-only, active handle, or old file state remains plausible.

Use file Properties, restart comparison, optional Process Explorer search, then a backed-up rename baseline.

Folder test fails

One or more temporary operations are denied.

Inspect folder boundary

Parent access or a security control is implicated.

Record Security-tab entries and match a real protection event. Do not alter all of AppData.

Fresh file also fails

Old JSON content was not the cause.

Stop and report

Restore the preserved state and avoid deeper guessing.

Use the report template below or proceed to clean recovery only after the narrow evidence is saved.

Writable does not mean recognized.

An empty JSON object is a valid minimal document, but Luczystrap should create the baseline when possible. Repairing Windows access only proves that the file can be saved; Roblox independently decides which local flags it recognizes.

Roblox FastFlag Allowlist

Roblox says non-allowlisted entries in ClientAppSettings.json are simply ignored. A successful write cannot restore an obsolete pack or turn a restricted flag into an allowed one.

Minimal valid JSON · reference only
{}
Syntax

One JSON object; no comments, trailing commas, or duplicate experiments during recovery.

Scope

Start empty, then add only current allowlisted settings you can identify.

Rollback

Keep the untouched dated backup until save, launch, and restart all pass.

A repair is finished only when the whole write survives.

Passing one save dialog is not enough. Check the file, launcher, Player, and restart boundary before restoring the rest of the configuration.

Save completes without UnauthorizedAccessException

Repeat the same action that originally failed.

Write passed
ClientAppSettings.json has a new timestamp and valid JSON

Confirm the intended path changed, not another copy.

Object passed
Roblox launches from Luczystrap

The bootstrapper applies the fresh configuration without another file error.

Launch passed
One current allowlisted setting behaves as expected

This separates a working write from Roblox ignoring a restricted flag.

Policy passed
The result survives one Windows restart

Do not discard the backup before persistence is confirmed.

Recovery passed

Shortcuts that create a larger problem.

These changes broaden access, remove evidence, or combine unrelated repairs. None is supported as a universal solution by the seven matching issues.

  • Do not run takeown or recursive icacls against AppData.

    That can alter inheritance for unrelated applications and removes the original ACL evidence.

  • Do not exclude the entire Luczystrap or Roblox folder.

    Microsoft warns exclusions reduce protection; require a matching event and choose the narrowest verified decision.

  • Do not make “Run as administrator” permanent.

    Elevation changes the token and can conceal the actual user-path problem.

  • Do not delete every Versions directory.

    The exception may concern the modifications source, one deployed copy, or official Roblox. The path chooses the object.

  • Do not restore a large old FastFlag pack at once.

    It hides whether the repair failed, the JSON broke, or Roblox ignored restricted entries.

Make the next report diagnosable.

The existing issue bodies are too sparse to establish a shared cause. A complete path, operation, and controlled comparison give maintainers evidence they can use.

ClientAppSettings access report
Luczystrap version:
Windows version:
Error timestamp and timezone:
Complete exception and HRESULT:
Full ClientAppSettings.json path:
Operation before failure:
Restart changed result: yes / no
Parent-folder create/rename/remove test:
Exact file Read-only state:
Security-tab owner/inheritance observation:
Matching Defender or antivirus event: yes / no
Fresh baseline saved: yes / no / not attempted
Roblox launched from Luczystrap: yes / no
Allowlisted test flag used:
Backup created at:
Logs attached:
Redact before posting: Windows usernames, account identifiers, cookies, tokens, webhook URLs, proxy credentials, and unrelated personal paths. Keep versions, timestamps, exception frames, filenames, and the product-owned path structure.

ClientAppSettings access denied FAQ

What is the fastest safe fix for ClientAppSettings.json access denied?

Preserve the exact path and log, close Luczystrap and Roblox, restart Windows once, and retry the same save. If that works without another change, a temporary process or file-use conflict is more plausible than a permanent permission problem.

Where is Luczystrap's ClientAppSettings.json file?

A detailed Luczystrap 1.4.9 log shows its working copy at %LocalAppData%\Luczystrap\Modifications\ClientSettings\ClientAppSettings.json. A deployed copy may also exist inside a version directory. Always use the complete path printed by your own exception because the filename alone does not identify the failed copy.

Does the Read-only checkbox prove the cause?

No. A read-only attribute on the exact file can prevent a write, but a folder's Read-only checkbox is not a reliable summary of NTFS authorization. Record the file attribute, parent-folder write test, Security tab, and any matching security event before choosing a repair.

Can I delete ClientAppSettings.json and start over?

Do not delete your only copy. Back it up first. If the parent folder is writable and the file is not locked, move the old file aside under a non-JSON backup name and let Luczystrap create a baseline. Keep the backup until save, launch, restart, and staged restore all pass.

Should I always run Luczystrap as administrator?

No. Permanent elevation can hide a user-path ownership or access problem without repairing it, and it raises the effective privilege of code loaded by the application. Ordinary FastFlag configuration in a user-owned Luczystrap folder should not require always-on administrator mode.

Can antivirus or Controlled Folder Access cause this error?

They are possible only when their history shows a matching event for the same application, path, action, and time. Check Windows Security Protection history or the active third-party product. Do not disable protection or exclude an entire folder without that evidence.

Why are my FastFlags still ignored after the file saves?

Windows write access and Roblox FastFlag recognition are separate boundaries. Roblox says only flags on its current allowlist are recognized from ClientAppSettings.json; non-allowlisted entries are ignored even when the JSON saves successfully.

What should I report if the error remains?

Include Luczystrap and Windows versions, the full exception and stack trace, exact file path, timestamp, whether restart changed the result, whether the parent-folder write test passed, the file's Read-only state, relevant Security-tab observations, any matching security event, and whether a fresh empty baseline saved and launched. Redact usernames and secrets.