Very interesting. Thanks for reporting. The request is being flagged as malicious and blocked by Cloudflare. It uses the same error code as not being logged in which confuses the FE.
The site has been updated to catch and display the correct error message if someone runs into this. Thanks again for reporting. I'll look into loosening firewall settings later.
Yes, changes could be made to the firewall to allow these through. I also want to update the front-end to detect CF responses and display them appropriately.