anthropics / anthropics/claude-code

[BUG] OAuth "Invalid code" error directs users to check length; actual cause is a missing "#" delimiter

オープン
#91,157 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
area:auth bug has repro platform:macos
主要言語
Python
スター
145k
フォーク
23.1k
PR マージ指標
PR 指標を取得中

説明

## What's Wrong?

The manual OAuth paste flow rejects input with:

OAuth error: Invalid code. Please make sure the full code was copied

The message directs the user to verify the code's **length**. The actual failure
condition is a missing `#` delimiter, which no length check can detect. A user whose
pasted value is long and complete-looking has no way to self-diagnose, producing an
unresolvable retry loop.

From the shipping binary, the parser is:

let [code, state] = input.trim().split("#");
if (!code || !state) { error("Invalid code. Please make sure the full code was copied") }

Input must contain `#` with non-empty content on both sides (`#`).

The delimiter is easy to lose for two reasons, both invisible to the user:
1. `#` is a word boundary — double-click selection stops before `#state`.
2. `#` is the URL fragment delimiter — any URL normalization drops everything after it.

## What Should Happen?

The error should name the actual condition and how to fix it. Suggested:

"Code must be in the form `code#state`. Copy the entire value, including the `#`
and everything after it. Tip: `#` is a word boundary — double-clicking selects
only the first half."

And distinguish the two failure modes: missing delimiter vs. one side empty.

## Error Messages / Logs

OAuth error: Invalid code. Please make sure the full code was copied

Press Enter to retry.

Two clipboard states captured during live failures on this machine:
attempt 1 : 346 chars, contains '#': NO -> rejected
attempt 2 : 1084 chars, contains '#': NO -> rejected
Both were long and untruncated. Both failed on the delimiter alone.

## Steps to Reproduce

1. Run `claude` in a terminal and start the login flow.
2. When the authorize page displays the code, **double-click** the code to select it
(this is the natural gesture and selects only up to the `#`).
3. Copy, and paste at the `Paste code here if prompted >` prompt.
4. Observe: "Invalid code. Please make sure the full code was copied"
5. Verify the clipboard was NOT truncated:
pbpaste | wc -c # long
pbpaste | grep -c '#' # 0 <- the actual cause
6. Following the message's advice (checking the code is "full") confirms it looks
complete and returns you to step 4.

## Additional Information

Ruled out during diagnosis: browser-specific behavior (reproduces in multiple browsers
including a fresh in-app browser), network interception (the authorize URL is built from
client constants and printed before any network request is made), and credential expiry
(credentials were valid throughout).

---

### Environment

| | |
|---|---|
| Claude Code | 2.1.212 (Claude Code) |
| Platform | Claude API (Max subscription) |
| OS | macOS 27.0 (build 26A5425a, developer beta) |
| Hardware | Apple M2 Pro, arm64 |
| Terminal / Shell | Ghostty 1.3.1 / zsh (also reproduced in Terminal.app) |
| Model | Opus |
| Regression | No — not tested against a prior version |

**Preflight:** searched existing issues; single bug report; on latest version.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

調査の方向性

Start at the manual OAuth paste flow and the parser shown in the report, then trace the `claude` login flow to the source of the current error. Update the feedback so the delimiter and empty-side failure modes are distinguishable, and verify the message for malformed and valid `code#state` input.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
python
領域
authentication, cli
issue の種類
バグ
難易度
2/5
見積もり時間
1〜3時間
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
55/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。