ruvnet/ruflo · info · LoginCancelledError

login cancelled: no code was entered

Error message

login cancelled: no code was entered

What it means

LoginCancelledError fires only in the manual (OOB paste-the-code) flow: manualLogin prompted 'Paste the code shown after authorizing:' and got an empty line — the user pressed Enter on nothing, or stdin hit EOF (the readline interface is explicitly raced against 'close' so early EOF resolves to '' instead of hanging). It represents an intentional or environment-driven cancellation, not a server failure.

Solutions

  1. If interactive: re-run `ruflo auth login`, open the printed URL, and paste the code at the prompt
  2. If scripted: feed the code via stdin (echo "$CODE" | ruflo auth login --manual or the equivalent programmatic manualLogin call) — or better, use --token-stdin with a JSON token
  3. Catch LoginCancelledError and exit with a benign code (0/130) — cancellation is not an error state for the user
  4. Ensure the environment isn't headless-triggering the manual flow when a browser is actually available (isProbablyHeadless false-negatives)

Example fix

// before — cancellation treated as a crash
const result = await manualLogin(print);

// after — graceful exit on cancellation
try {
  const result = await manualLogin(print);
} catch (e) {
  if (e instanceof LoginCancelledError) { print('Login cancelled.'); process.exit(130); }
  throw e;
}
Defensive patterns

Strategy: try-catch

Validate before calling

// scripted manual login: provide the code on stdin so the prompt never sees EOF
const result = await manualLogin(print, Readable.from([`${code}\n`]));

Try / catch

import { LoginCancelledError } from './auth/client.js';

try { await manualLogin(print); }
catch (e) {
  if (e instanceof LoginCancelledError) { process.exit(130); /* benign cancel */ }
  throw e;
}

Prevention

When it happens

Trigger: manualLogin(print, input) where input closes before any code is typed: pressing Enter at the empty prompt, Ctrl-D/Ctrl-C terminating stdin, a piped stdin with no content (manualLogin </dev/null), or scripts invoking the manual flow non-interactively without supplying the code.

Common situations: Headless/SSH sessions where the manual fallback triggers but no TTY input is available; automation piping empty stdin; users confused by the prompt and hitting Enter; CI jobs accidentally choosing the device/manual path.

Related errors


AI-assisted analysis of ruvnet/ruflo@fa13ee4ad6 (2026-08-18). Data as JSON: /api/errors/ed4ecb6e17f20418. Report an issue: GitHub.

Appendix: source

Thrown at v3/@claude-flow/cli/src/auth/client.ts:165

  const pkce = sec.generatePkce();
  const url = sec.authorizeUrl(sec.OOB_REDIRECT_URI, pkce.state, pkce.codeChallenge);
  print(`Open this URL in a browser and authorize:\n\n  ${url}\n`);

  // `rl.question()` resolves on a newline-terminated 'line' event — if `input`
  // ends without ever emitting one (e.g. stdin closed early, or piped input
  // with no trailing newline), it hangs forever rather than treating EOF as
  // a cancellation. Race it against the interface's own 'close' event so an
  // early EOF resolves to "" (-> LoginCancelledError below) instead of hanging.
  const rl = readline.createInterface({ input, terminal: false });
  let code: string;
  try {
    const closed = new Promise<string>((resolve) => rl.once('close', () => resolve('')));
    code = (await Promise.race([rl.question('Paste the code shown after authorizing: '), closed])).trim();
  } finally {
    rl.close();
  }
  if (!code) throw new LoginCancelledError();

  const tokens = await sec.exchangeManualCode(code, pkce.codeVerifier);
  return { tokens, method: 'device' };
}

/**
 * `--token-stdin`: reads one JSON object from stdin,
 * `{access_token, refresh_token?, expires_in, scope}`. Wire format is not
 * specified by ADR-306 — defined here as typed JSON rather than a bare
 * token string, so scope/expiry are explicit rather than inferred.
 */
export async function tokenStdinLogin(input: NodeJS.ReadableStream = process.stdin): Promise<LoginResult> {
  const chunks: Buffer[] = [];
  for await (const chunk of input) chunks.push(chunk as Buffer);
  const raw = Buffer.concat(chunks).toString('utf-8').trim();
  if (!raw) throw new Error('--token-stdin: no input received on stdin');

  let parsed: { access_token?: string; refresh_token?: string; expires_in?: number; scope?: string };

View on GitHub (pinned to fa13ee4ad6)