{"record":{"id":"d2a6fc2992420c0b","repo":"ruvnet/ruflo","slug":"ruflo-auth-needs-the-claude-flow-security-packa","errorCode":null,"errorMessage":"ruflo auth needs the '@claude-flow/security' package, which isn't installed (it's an optional dependency — install/reinstall failed or was skipped for this platform). Try: npm install @claude-flow/security. Underlying error: ${cause instanceof Error ? cause.message : String(cause)}","messagePattern":"ruflo auth needs the '@claude-flow/security' package, which isn't installed \\(it's an optional dependency — install/reinstall failed or was skipped for this platform\\)\\. Try: npm install @claude-flow/security\\. Underlying error: (.+?)","errorType":"exception","errorClass":"SecurityPackageMissingError","httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/auth/security-bridge.ts","lineNumber":75,"sourceCode":"    );\n    this.name = 'SecurityPackageMissingError';\n  }\n}\n\nlet cached: SecurityOAuthModule | null = null;\n\n/** Loads `@claude-flow/security`'s OAuth surface, throwing a clear error if it's absent. */\nexport async function loadSecurityOAuth(): Promise<SecurityOAuthModule> {\n  if (cached) return cached;\n  try {\n    const mod = (await import('@claude-flow/security')) as unknown as SecurityOAuthModule;\n    if (!mod.authorizeUrl || !mod.createKeychainAdapter) {\n      throw new Error('module loaded but is missing expected OAuth exports');\n    }\n    cached = mod;\n    return mod;\n  } catch (e) {\n    throw new SecurityPackageMissingError(e);\n  }\n}\n","sourceCodeStart":57,"sourceCodeEnd":78,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/auth/security-bridge.ts#L57-L78","documentation":"SecurityPackageMissingError from loadSecurityOAuth(): the dynamic import('@claude-flow/security') failed outright. The package is an optionalDependency (so core ruflo works without it), but `ruflo auth` cannot — this error converts a raw ERR_MODULE_NOT_FOUND into an actionable install instruction, preserving the underlying cause message.","triggerScenarios":"Any auth flow (browserLogin, device, token-stdin path via loadSecurityOAuth, refresh) when @claude-flow/security is absent from node_modules: install ran with --no-optional / --omit=optional, the platform-specific install step failed or was skipped, or the package was pruned.","commonSituations":"CI or production images installing with npm ci --omit=optional or NODE_ENV production pruning optionals; yarn/pnpm hoisting quirks dropping optional deps; installing on a platform where a transitive native dependency of the security package fails to build; users who installed a slim/partial tarball.","solutions":["npm install @claude-flow/security (as the message says)","If installs keep skipping it, install without --no-optional/--omit=optional and check npm config get omit","Check the Underlying error text at the end of the message — a build failure in a transitive dep points to toolchain prerequisites","Verify afterwards: node -e \"import('@claude-flow/security').then(() => console.log('ok'))\""],"exampleFix":"# before\nNODE_ENV=production npm ci --omit=optional\nruflo auth login   # SecurityPackageMissingError\n# after\nnpm ci\nnpm install @claude-flow/security\nruflo auth login","handlingStrategy":"try-catch","validationCode":"// Pre-flight: fail fast with your own message if the optional dep is absent\ntry { await import('@claude-flow/security'); }\ncatch { throw new Error('auth features require @claude-flow/security — run npm install @claude-flow/security'); }","typeGuard":"import { SecurityPackageMissingError } from '@claude-flow/cli/dist/auth/security-bridge.js';\nfunction isSecurityPackageMissing(e: unknown): e is SecurityPackageMissingError {\n  return e instanceof Error && e.name === 'SecurityPackageMissingError';\n}","tryCatchPattern":"try {\n  await runAuthCommand();\n} catch (e) {\n  if (isSecurityPackageMissing(e)) {\n    // e.message already includes the install command and the underlying cause\n    console.error(e.message);\n    process.exit(5);\n  }\n  throw e;\n}","preventionTips":["Never install with --omit=optional/--no-optional if auth is needed","Add a postinstall check or Docker layer verifying import('@claude-flow/security') resolves","Read the trailing 'Underlying error:' text — it distinguishes not-installed from broken-install"],"tags":["auth","dependency","optional-dependency","npm","install"],"backgroundTag":"missing-optional-dependency","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}