ruvnet/ruflo · info · LoginCancelledError
login cancelled: no code was entered
Error message
login cancelled: no code was entered
What it means
LoginCancelledError fires only in the manual (OOB paste-the-code) flow: manualLogin prompted 'Paste the code shown after authorizing:' and got an empty line — the user pressed Enter on nothing, or stdin hit EOF (the readline interface is explicitly raced against 'close' so early EOF resolves to '' instead of hanging). It represents an intentional or environment-driven cancellation, not a server failure.
Solutions
- If interactive: re-run `ruflo auth login`, open the printed URL, and paste the code at the prompt
- If scripted: feed the code via stdin (echo "$CODE" | ruflo auth login --manual or the equivalent programmatic manualLogin call) — or better, use --token-stdin with a JSON token
- Catch LoginCancelledError and exit with a benign code (0/130) — cancellation is not an error state for the user
- Ensure the environment isn't headless-triggering the manual flow when a browser is actually available (isProbablyHeadless false-negatives)
Example fix
// before — cancellation treated as a crash
const result = await manualLogin(print);
// after — graceful exit on cancellation
try {
const result = await manualLogin(print);
} catch (e) {
if (e instanceof LoginCancelledError) { print('Login cancelled.'); process.exit(130); }
throw e;
} Defensive patterns
Strategy: try-catch
Validate before calling
// scripted manual login: provide the code on stdin so the prompt never sees EOF
const result = await manualLogin(print, Readable.from([`${code}\n`])); Try / catch
import { LoginCancelledError } from './auth/client.js';
try { await manualLogin(print); }
catch (e) {
if (e instanceof LoginCancelledError) { process.exit(130); /* benign cancel */ }
throw e;
} Prevention
- When scripting the manual flow, pipe the code in rather than relying on a TTY
- Treat cancellation as exit code 130/0, not a failure
- Ensure headless detection doesn't force the manual path when a browser exists
When it happens
Trigger: manualLogin(print, input) where input closes before any code is typed: pressing Enter at the empty prompt, Ctrl-D/Ctrl-C terminating stdin, a piped stdin with no content (manualLogin </dev/null), or scripts invoking the manual flow non-interactively without supplying the code.
Common situations: Headless/SSH sessions where the manual fallback triggers but no TTY input is available; automation piping empty stdin; users confused by the prompt and hitting Enter; CI jobs accidentally choosing the device/manual path.
Related errors
- not logged in for profile
- --token-stdin: JSON is missing required field "access_token"
- --token-stdin: no input received on stdin
- authorization was denied or failed
- Cognitum auth service returned an unexpected response
AI-assisted analysis of ruvnet/ruflo@fa13ee4ad6 (2026-08-18).
Data as JSON: /api/errors/ed4ecb6e17f20418.
Report an issue: GitHub.
Appendix: source
Thrown at v3/@claude-flow/cli/src/auth/client.ts:165
const pkce = sec.generatePkce();
const url = sec.authorizeUrl(sec.OOB_REDIRECT_URI, pkce.state, pkce.codeChallenge);
print(`Open this URL in a browser and authorize:\n\n ${url}\n`);
// `rl.question()` resolves on a newline-terminated 'line' event — if `input`
// ends without ever emitting one (e.g. stdin closed early, or piped input
// with no trailing newline), it hangs forever rather than treating EOF as
// a cancellation. Race it against the interface's own 'close' event so an
// early EOF resolves to "" (-> LoginCancelledError below) instead of hanging.
const rl = readline.createInterface({ input, terminal: false });
let code: string;
try {
const closed = new Promise<string>((resolve) => rl.once('close', () => resolve('')));
code = (await Promise.race([rl.question('Paste the code shown after authorizing: '), closed])).trim();
} finally {
rl.close();
}
if (!code) throw new LoginCancelledError();
const tokens = await sec.exchangeManualCode(code, pkce.codeVerifier);
return { tokens, method: 'device' };
}
/**
* `--token-stdin`: reads one JSON object from stdin,
* `{access_token, refresh_token?, expires_in, scope}`. Wire format is not
* specified by ADR-306 — defined here as typed JSON rather than a bare
* token string, so scope/expiry are explicit rather than inferred.
*/
export async function tokenStdinLogin(input: NodeJS.ReadableStream = process.stdin): Promise<LoginResult> {
const chunks: Buffer[] = [];
for await (const chunk of input) chunks.push(chunk as Buffer);
const raw = Buffer.concat(chunks).toString('utf-8').trim();
if (!raw) throw new Error('--token-stdin: no input received on stdin');
let parsed: { access_token?: string; refresh_token?: string; expires_in?: number; scope?: string };View on GitHub (pinned to fa13ee4ad6)