ruvnet/ruflo · error · Error
approval issuance requires an authenticated human identity…
Error message
approval issuance requires an authenticated human identity adapter; the local TTY is not an identity credential
What it means
The `policy approve` subcommand is intentionally unimplemented and throws unconditionally: issuing an approval requires an authenticated human identity adapter, and the local TTY is explicitly not accepted as an identity credential (ADR-324 security posture). This is a deliberate design decision, not a bug or missing dependency — no flag combination can make it succeed.
Solutions
- Do not route approvals through the CLI — use the consuming application's identity-adapter-based approval flow
- If an approval was issued elsewhere and must be undone, `policy revoke <id>` works from an interactive terminal
- Track the ADR-324 identity-adapter milestone for when CLI-issued approvals become supported
Defensive patterns
Strategy: fallback
Try / catch
try {
await runPolicyCli(['policy', 'approve', id]);
} catch (err) {
if (err instanceof Error && err.message.includes('identity adapter')) {
// route the approval through the application's identity-adapter flow instead
} else throw err;
} Prevention
- Never build automation on the CLI approve path — it throws unconditionally by design
- Model approvals in your own service using policy-runtime, keeping the CLI for revoke/audit
- Watch ADR-324 releases for the identity adapter that will enable CLI approvals
When it happens
Trigger: Any invocation of `ruflo policy approve <anything>` — the branch throws before looking at arguments, environment, or state.
Common situations: Assuming approve/revoke are symmetric (revoke works from a TTY); attempting to script the human-approval step of a policy workflow from CI or an agent.
Understand the failure class
Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- policy administration requires an authenticated user context
- policy administration requires an interactive local terminal
- policy- : ; receipt=
- self-approval-forbidden
- untrusted-approval-issuer
AI-assisted analysis of ruvnet/ruflo@fa13ee4ad6 (2026-08-18).
Data as JSON: /api/errors/038ae0bcad96a5f4.
Report an issue: GitHub.
Appendix: source
Thrown at v3/@claude-flow/cli/src/commands/policy.ts:89
});
}
if (operation === 'evaluate') {
return print(await evaluatePolicyRequest(argJson<PolicyRequest>(args[1], 'evaluate'), root));
}
if (operation === 'rule' && args[1] === 'add') {
requireInteractiveAdministrator();
const rule = argJson<PolicyRule>(args[2], 'rule add');
await upsertPolicyRule(rule, root);
return print({ success: true, ruleId: rule.id });
}
if (operation === 'budget' && args[1] === 'set') {
requireInteractiveAdministrator();
const budget = argJson<BudgetLimit>(args[2], 'budget set');
await setPolicyBudget(budget, root);
return print({ success: true, budgetId: budget.id });
}
if (operation === 'approve') {
throw new Error(
'approval issuance requires an authenticated human identity adapter; '
+ 'the local TTY is not an identity credential',
);
}
if (operation === 'revoke') {
requireInteractiveAdministrator();
if (!args[1]) throw new Error('revoke requires an approval id');
return print({ success: await revokePolicyApproval(args[1], root), approvalId: args[1] });
}
if (operation === 'audit') {
const state = loadPolicyState(root);
return print({ receipts: state.receipts });
}
if (operation === 'verify') return print(await verifyPolicyLedger(root));
throw new Error(`unknown policy operation: ${operation}`);
} catch (error) {
const message = error instanceof Error ? error.message : String(error);
output.printError(message);View on GitHub (pinned to fa13ee4ad6)