auth/credentials: Avoid double-free in the failure case