Is there an existing issue for this?
This issue exists in the latest npm version
This is not just a request to bump a dependency for a CVE
Current Behavior
When npm has a 401 error, it constructs an error message that suggests recovering your password. But this error message has a hard-coded https://npmjs.org link, which is misleading when the authentication error occurred with a private npm registry, not the default npmjs.org registry.
Expected Behavior
The error message should display a link to the root of the custom registry if it is set, and fall back to the default https://npmjs.org/forgot. Note the custom registry likely won't be able to point to a /forgot subpage, but defaulting to the root of the custom registry would be more clear.
The reasoning for this request is that it is confusing for developers experiencing auth errors to see a link to the public npm registry when our team exclusively uses an internal mirror.
Steps To Reproduce
- Set up a .npmrc to point to an npm registry that requires authentication
- Make an npm install WITHOUT authenticating
- It should return a 401 with the error
npm error code E401
npm error Incorrect or missing password.
npm error If you were trying to login, change your password, create an authentication token or enable two-factor authentication then that means you likely typed your password in incorrectly.
npm error Please try again, or recover your password at:
npm error https://www.npmjs.com/forgot
npm error
npm error If you were doing some other operation then your saved credentials are probably out of date.
npm error To correct this please try logging in again with:
npm error npm login
npm error A complete log of this run can be found in: /home/kmurphy/.npm/_logs/2026-09-22T16_19_31_269Z-debug-0.log
The source code for the hard-coded error message is at:
|
' https://www.npmjs.com/forgot', |
Environment
- npm: 12.0.1
- Node.js: 26.10.0
- OS Name: Ubuntu 24.04
- System Model Name: all
- npm config:
; "user" config from /home/kmurphy/.npmrc
; //artifactory.mydomain.com/artifactory/api/npm/my-npm-mirror/:_authToken = (protected) ; overridden by project
; "project" config from /home/kmurphy/dev/MyProject/MySubdir/.npmrc
//artifactory.mydomain.com/artifactory/api/npm/my-npm-mirror/:_authToken = (protected)
registry = "https://artifactory.mydomain.com/artifactory/api/npm/my-npm-mirror/"
; node bin location = /home/kmurphy/.nvm/versions/node/v26.10.0/bin/node
; node version = v26.10.0
; npm local prefix = /home/kmurphy/dev/MyProject/MySubdir
; npm version = 12.0.2
; cwd = /home/kmurphy/dev/MyProject/MySubdir
; HOME = /home/kmurphy
; Run `npm config ls -l` to show all defaults.
Is there an existing issue for this?
This issue exists in the latest npm version
This is not just a request to bump a dependency for a CVE
Current Behavior
When npm has a 401 error, it constructs an error message that suggests recovering your password. But this error message has a hard-coded
https://npmjs.orglink, which is misleading when the authentication error occurred with a private npm registry, not the default npmjs.org registry.Expected Behavior
The error message should display a link to the root of the custom registry if it is set, and fall back to the default
https://npmjs.org/forgot. Note the custom registry likely won't be able to point to a/forgotsubpage, but defaulting to the root of the custom registry would be more clear.The reasoning for this request is that it is confusing for developers experiencing auth errors to see a link to the public npm registry when our team exclusively uses an internal mirror.
Steps To Reproduce
The source code for the hard-coded error message is at:
cli/lib/utils/error-message.js
Line 159 in 7b50811
Environment