{"record":{"id":"32a9ddc22f929618","repo":"microsoft/playwright","slug":"clientcertificates-origin-is-required","errorCode":null,"errorMessage":"clientCertificates.origin is required","messagePattern":"clientCertificates\\.origin is required","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/playwright-core/src/server/browserContext.ts","lineNumber":814,"sourceCode":"export function verifyGeolocation(geolocation?: types.Geolocation): asserts geolocation is types.Geolocation {\n  if (!geolocation)\n    return;\n  geolocation.accuracy = geolocation.accuracy || 0;\n  const { longitude, latitude, accuracy } = geolocation;\n  if (longitude < -180 || longitude > 180)\n    throw new Error(`geolocation.longitude: precondition -180 <= LONGITUDE <= 180 failed.`);\n  if (latitude < -90 || latitude > 90)\n    throw new Error(`geolocation.latitude: precondition -90 <= LATITUDE <= 90 failed.`);\n  if (accuracy < 0)\n    throw new Error(`geolocation.accuracy: precondition 0 <= ACCURACY failed.`);\n}\n\nexport function verifyClientCertificates(clientCertificates?: types.BrowserContextOptions['clientCertificates']) {\n  if (!clientCertificates)\n    return;\n  for (const cert of clientCertificates) {\n    if (!cert.origin)\n      throw new Error(`clientCertificates.origin is required`);\n    if (cert.noCertificate) {\n      if (cert.cert || cert.key || cert.passphrase || cert.pfx)\n        throw new Error('noCertificate is set together with cert, key, passphrase or pfx');\n      continue;\n    }\n    if (!cert.cert && !cert.key && !cert.passphrase && !cert.pfx)\n      throw new Error('None of cert, key, passphrase or pfx is specified');\n    if (cert.cert && !cert.key)\n      throw new Error('cert is specified without key');\n    if (!cert.cert && cert.key)\n      throw new Error('key is specified without cert');\n    if (cert.pfx && (cert.cert || cert.key))\n      throw new Error('pfx is specified together with cert, key or passphrase');\n  }\n}\n\nexport function normalizeProxySettings(proxy: types.ProxySettings): types.ProxySettings {\n  let { server, bypass } = proxy;","sourceCodeStart":796,"sourceCodeEnd":832,"githubUrl":"https://github.com/microsoft/playwright/blob/f1d33b5029be8bbc1095fe88e559117fa3a6243b/packages/playwright-core/src/server/browserContext.ts#L796-L832","documentation":"A validation error thrown while parsing the browser context options: an entry in the clientCertificates array was provided without an origin field. Each certificate entry must declare which origin(s) it applies to, so Playwright can decide when to present it during TLS authentication; an entry with a certificate/key but no origin is unusable and rejected at context creation time.","triggerScenarios":"`browser.newContext({ clientCertificates: [{ cert: '...', key: '...' }] })` — an entry missing the `origin` field.","commonSituations":"Incomplete TLS client-auth configs; assuming Playwright applies certs globally rather than per-origin; partial refactor of cert loading.","solutions":["Add `origin: 'https://host'` to each clientCertificates entry","Group cert/key/passphrase/pfx under the correct origin","Validate each entry has origin before launching the context"],"exampleFix":"// before\nawait browser.newContext({\n  clientCertificates: [{ cert: 'c.pem', key: 'k.pem' }]\n});\n\n// after\nawait browser.newContext({\n  clientCertificates: [{ origin: 'https://example.com', cert: 'c.pem', key: 'k.pem' }]\n});","handlingStrategy":"validation","validationCode":"function validateClientCerts(certs?: { origin?: string; cert?: string; key?: string; passphrase?: string; pfx?: string }[]) {\n  if (!certs) return;\n  for (const c of certs) {\n    if (!c.origin) throw new Error('Each clientCertificates entry requires an `origin` (e.g. https://host).');\n    if (!c.cert && !c.key && !c.passphrase && !c.pfx)\n      throw new Error(`clientCertificates entry for ${c.origin} has no cert/key/passphrase/pfx`);\n    if (c.cert && !c.key) throw new Error(`cert requires key for ${c.origin}`);\n    if (!c.cert && c.key) throw new Error(`key requires cert for ${c.origin}`);\n    if (c.pfx && (c.cert || c.key)) throw new Error(`pfx is exclusive of cert/key for ${c.origin}`);\n  }\n}\nvalidateClientCerts(opts.clientCertificates);\nawait browser.newContext(opts);","typeGuard":"function isValidCertEntry(c: unknown): c is { origin: string; cert?: string; key?: string; passphrase?: string; pfx?: string } {\n  return !!c && typeof c === 'object' && typeof (c as any).origin === 'string' && (c as any).origin.length > 0;\n}","tryCatchPattern":null,"preventionTips":["Always include `origin` on every clientCertificates entry","Validate the full cert/key/pfx matrix before launch","Centralize TLS config validation to fail fast with a clear message"],"tags":["client-certificates","validation","config","tls"],"backgroundTag":null,"analyzedSha":"f1d33b5029be8bbc1095fe88e559117fa3a6243b","analyzedAt":"2026-09-15T07:37:15.003Z","contentChangedAt":"2026-09-15T07:37:15.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}