{"record":{"id":"038ae0bcad96a5f4","repo":"ruvnet/ruflo","slug":"approval-issuance-requires-an-authenticated-human","errorCode":null,"errorMessage":"approval issuance requires an authenticated human identity adapter; the local TTY is not an identity credential","messagePattern":"approval issuance requires an authenticated human identity adapter; the local TTY is not an identity credential","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/commands/policy.ts","lineNumber":89,"sourceCode":"        });\n      }\n      if (operation === 'evaluate') {\n        return print(await evaluatePolicyRequest(argJson<PolicyRequest>(args[1], 'evaluate'), root));\n      }\n      if (operation === 'rule' && args[1] === 'add') {\n        requireInteractiveAdministrator();\n        const rule = argJson<PolicyRule>(args[2], 'rule add');\n        await upsertPolicyRule(rule, root);\n        return print({ success: true, ruleId: rule.id });\n      }\n      if (operation === 'budget' && args[1] === 'set') {\n        requireInteractiveAdministrator();\n        const budget = argJson<BudgetLimit>(args[2], 'budget set');\n        await setPolicyBudget(budget, root);\n        return print({ success: true, budgetId: budget.id });\n      }\n      if (operation === 'approve') {\n        throw new Error(\n          'approval issuance requires an authenticated human identity adapter; '\n          + 'the local TTY is not an identity credential',\n        );\n      }\n      if (operation === 'revoke') {\n        requireInteractiveAdministrator();\n        if (!args[1]) throw new Error('revoke requires an approval id');\n        return print({ success: await revokePolicyApproval(args[1], root), approvalId: args[1] });\n      }\n      if (operation === 'audit') {\n        const state = loadPolicyState(root);\n        return print({ receipts: state.receipts });\n      }\n      if (operation === 'verify') return print(await verifyPolicyLedger(root));\n      throw new Error(`unknown policy operation: ${operation}`);\n    } catch (error) {\n      const message = error instanceof Error ? error.message : String(error);\n      output.printError(message);","sourceCodeStart":71,"sourceCodeEnd":107,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/commands/policy.ts#L71-L107","documentation":"The `policy approve` subcommand is intentionally unimplemented and throws unconditionally: issuing an approval requires an authenticated human identity adapter, and the local TTY is explicitly not accepted as an identity credential (ADR-324 security posture). This is a deliberate design decision, not a bug or missing dependency — no flag combination can make it succeed.","triggerScenarios":"Any invocation of `ruflo policy approve <anything>` — the branch throws before looking at arguments, environment, or state.","commonSituations":"Assuming approve/revoke are symmetric (revoke works from a TTY); attempting to script the human-approval step of a policy workflow from CI or an agent.","solutions":["Do not route approvals through the CLI — use the consuming application's identity-adapter-based approval flow","If an approval was issued elsewhere and must be undone, `policy revoke <id>` works from an interactive terminal","Track the ADR-324 identity-adapter milestone for when CLI-issued approvals become supported"],"exampleFix":null,"handlingStrategy":"fallback","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  await runPolicyCli(['policy', 'approve', id]);\n} catch (err) {\n  if (err instanceof Error && err.message.includes('identity adapter')) {\n    // route the approval through the application's identity-adapter flow instead\n  } else throw err;\n}","preventionTips":["Never build automation on the CLI approve path — it throws unconditionally by design","Model approvals in your own service using policy-runtime, keeping the CLI for revoke/audit","Watch ADR-324 releases for the identity adapter that will enable CLI approvals"],"tags":["cli","policy","authorization","not-implemented","security"],"backgroundTag":"unsupported-operation","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}