{"record":{"id":"46b0c844ab59533f","repo":"affaan-m/ECC","slug":"no-browser-is-valid-only-for-ecc-ito-login-auth","errorCode":null,"errorMessage":"--no-browser is valid only for ecc ito login; auth is validation-only.","messagePattern":"--no-browser is valid only for ecc ito login; auth is validation-only\\.","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"scripts/ito.js","lineNumber":171,"sourceCode":"      \"Itô compute has no paper or dry-run success mode. No CLI operation was invoked.\"\n    );\n  }\n\n  const jsonIndexes = args\n    .map((value, index) => (value === \"--json\" ? index : -1))\n    .filter((index) => index >= 0);\n  if (jsonIndexes.length > 1) {\n    throw new Error(\"--json may only be provided once\");\n  }\n  const withoutJson = args.filter((value) => value !== \"--json\");\n  const command = withoutJson.shift();\n  if (!SUPPORTED_COMMANDS.includes(command)) {\n    throw new Error(\n      `Unsupported Itô command \"${command || \"(missing)\"}\"; ECC permits only login, logout, auth, find, status, and evals.`\n    );\n  }\n  if (command === \"auth\" && withoutJson.includes(\"--no-browser\")) {\n    throw new Error(\"--no-browser is valid only for ecc ito login; auth is validation-only.\");\n  }\n  if (command === \"evals\") {\n    validateNodeQualificationArgs(withoutJson, environment);\n  }\n\n  return Object.freeze({\n    help: false,\n    invocationArgs: Object.freeze([\n      ...(jsonIndexes.length === 1 ? [\"--json\"] : []),\n      command,\n      ...withoutJson,\n    ]),\n  });\n}\n\nfunction resolveItoExecutable(environment = process.env) {\n  const configured = environment[EXECUTABLE_OVERRIDE]?.trim();\n  if (!configured) {","sourceCodeStart":153,"sourceCodeEnd":189,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/scripts/ito.js#L153-L189","documentation":"parseArgs rejects --no-browser when used with the auth command; the flag is only meaningful for `ecc ito login`, because auth is validation-only and never opens a browser. This enforces mutually exclusive flag/command semantics.","triggerScenarios":"Running `ecc ito auth --no-browser` — any invocation combining the auth command with the --no-browser flag.","commonSituations":"Copy-pasting a login invocation and swapping the command to auth while keeping its flags; headless CI scripts adding --no-browser defensively to every subcommand; assuming auth performs the interactive browser flow.","solutions":["Remove --no-browser from the auth invocation: `ecc ito auth`","If a non-interactive flow is needed, use `ecc ito login --no-browser` instead (the only command accepting the flag)","Strip command-inappropriate flags in wrapper scripts before dispatching"],"exampleFix":"// before\nconst cmd = ['auth', '--no-browser'];\n// after\nconst cmd = ['auth']; // or ['login', '--no-browser'] if browser-less login is intended","handlingStrategy":"validation","validationCode":"const BROWSERLESS = new Set(['login']);\nif (command === 'auth' && args.includes('--no-browser')) {\n  throw new Error('--no-browser is login-only');\n}","typeGuard":null,"tryCatchPattern":"try {\n  runIto([command, ...flags]);\n} catch (e) {\n  if (e.message.includes('--no-browser is valid only for')) {\n    runIto([command, ...flags.filter(f => f !== '--no-browser')]);\n  } else throw e;\n}","preventionTips":["Keep per-command flag whitelists in wrapper scripts","Do not blanket-add --no-browser to every subcommand in headless environments","Remember auth never opens a browser; only login accepts --no-browser"],"tags":["cli","flag-misuse","command-validation"],"backgroundTag":"mutually-exclusive-flags","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}