commit 5c0832e2de53e87f212d50fc4548857b693b5c70
parent 0f4d060598dc27c4f986a7ca8548ef14865d6920
Author: I Mean I'm Just Saying <imeanimjustsaying@kiwifarms.st>
Date: Tue, 6 Oct 2026 10:54:53 -0400
common: a malformed Cloudflare token reads as REFUSED too (codes 6003, 6111)
S5's real-wrangler smoke: CLOUDFLARE_API_TOKEN=bogus makes Cloudflare
answer "Invalid request headers [code: 6003]" / "Invalid format for
Authorization header [code: 6111]", which the classifier did not list, so
the deploy ended "FAILED — wrangler exited 1". Both are in
wranglerAuthFailureIn now (9109, a well-formed wrong token, already was),
each pinned by a line in pagesDeploy.test.ts.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Diffstat:
2 files changed, 14 insertions(+), 2 deletions(-)
diff --git a/common/lib/pagesDeploy.test.ts b/common/lib/pagesDeploy.test.ts
@@ -136,6 +136,10 @@ test("wranglerAuthFailureIn: Cloudflare's refusals and wrangler's missing-login
"✘ [ERROR] A request to the Cloudflare API (/accounts/x/pages/projects/y) failed. Authentication error [code: 10000]",
"Invalid access token [code: 9109]",
"Unable to authenticate request [code: 10001]",
+ // A malformed token (CLOUDFLARE_API_TOKEN=bogus, the container smoke):
+ " Invalid request headers [code: 6003]",
+ " Invalid format for Authorization header [code: 6111]",
+ "✘ [ERROR] A request to the Cloudflare API (/accounts/x/pages/projects/y) failed. Invalid request headers [code: 6003]",
"In a non-interactive environment, it's necessary to set a CLOUDFLARE_API_TOKEN environment variable for wrangler to work.",
"You are not authenticated. Please run `wrangler login`.",
"Failed to refresh OAuth token",
@@ -146,6 +150,8 @@ test("wranglerAuthFailureIn: Cloudflare's refusals and wrangler's missing-login
"✨ Success! Uploaded 12 files (40 already uploaded)",
"Project not found. The specified project name does not match any of your existing projects. [code: 8000007]",
"Take a peek over at https://abc123.anilyzer.pages.dev",
+ "Invalid request headers",
+ "[code: 6003]",
"",
]) {
assert.equal(wranglerAuthFailureIn(line), false, line);
diff --git a/common/lib/pagesDeploy.ts b/common/lib/pagesDeploy.ts
@@ -123,12 +123,18 @@ export const CLOUDFLARE_NO_CREDENTIALS =
// What wrangler 4 prints when Cloudflare rejects, or it cannot find, a
// credential: the API's own error codes (10000 "Authentication error", 9109
-// "Invalid access token", 10001 "Unable to authenticate request") and wrangler's
-// own sentences for a missing login in a non-interactive run.
+// "Invalid access token" — a well-formed token that is wrong — 10001 "Unable to
+// authenticate request", 6003 "Invalid request headers" and 6111 "Invalid format
+// for Authorization header" — a malformed one) and wrangler's own sentences for
+// a missing login in a non-interactive run.
const AUTH_FAILURE_RES: readonly RegExp[] = [
/Authentication error \[code: 10000\]/,
/Invalid access token \[code: 9109\]/,
/Unable to authenticate request \[code: 10001\]/,
+ // A malformed token (not a token's shape at all): Cloudflare rejects the
+ // header before it reads the credential (seen with CLOUDFLARE_API_TOKEN=bogus).
+ /Invalid request headers \[code: 6003\]/,
+ /Invalid format for Authorization header \[code: 6111\]/,
/necessary to set a CLOUDFLARE_API_TOKEN environment variable/,
/You are not authenticated\. Please run `wrangler login`/,
/Failed to refresh (?:the )?OAuth token/i,