{"record":{"id":"9989b5bed92798f9","repo":"microsoft/playwright","slug":"nocertificate-is-set-together-with-cert-key-passphrase-or","errorCode":null,"errorMessage":"noCertificate is set together with cert, key, passphrase or pfx","messagePattern":"noCertificate is set together with cert, key, passphrase or pfx","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/playwright-core/src/server/browserContext.ts","lineNumber":817,"sourceCode":"  geolocation.accuracy = geolocation.accuracy || 0;\n  const { longitude, latitude, accuracy } = geolocation;\n  if (longitude < -180 || longitude > 180)\n    throw new Error(`geolocation.longitude: precondition -180 <= LONGITUDE <= 180 failed.`);\n  if (latitude < -90 || latitude > 90)\n    throw new Error(`geolocation.latitude: precondition -90 <= LATITUDE <= 90 failed.`);\n  if (accuracy < 0)\n    throw new Error(`geolocation.accuracy: precondition 0 <= ACCURACY failed.`);\n}\n\nexport function verifyClientCertificates(clientCertificates?: types.BrowserContextOptions['clientCertificates']) {\n  if (!clientCertificates)\n    return;\n  for (const cert of clientCertificates) {\n    if (!cert.origin)\n      throw new Error(`clientCertificates.origin is required`);\n    if (cert.noCertificate) {\n      if (cert.cert || cert.key || cert.passphrase || cert.pfx)\n        throw new Error('noCertificate is set together with cert, key, passphrase or pfx');\n      continue;\n    }\n    if (!cert.cert && !cert.key && !cert.passphrase && !cert.pfx)\n      throw new Error('None of cert, key, passphrase or pfx is specified');\n    if (cert.cert && !cert.key)\n      throw new Error('cert is specified without key');\n    if (!cert.cert && cert.key)\n      throw new Error('key is specified without cert');\n    if (cert.pfx && (cert.cert || cert.key))\n      throw new Error('pfx is specified together with cert, key or passphrase');\n  }\n}\n\nexport function normalizeProxySettings(proxy: types.ProxySettings): types.ProxySettings {\n  let { server, bypass } = proxy;\n  let url;\n  try {\n    // new URL('127.0.0.1:8080') throws","sourceCodeStart":799,"sourceCodeEnd":835,"githubUrl":"https://github.com/microsoft/playwright/blob/f1d33b5029be8bbc1095fe88e559117fa3a6243b/packages/playwright-core/src/server/browserContext.ts#L799-L835","documentation":"Playwright validates each clientCertificates entry when a browser context is created. A cert entry flagged with noCertificate=true is a 'deny/ignore certificates for this origin' marker and must not carry actual certificate material (cert, key, passphrase, pfx). Supplying both is contradictory, so the context creation fails fast in browserContext.ts.","triggerScenarios":"Calling browser.newContext({ clientCertificates: [{ origin: 'https://example.com', noCertificate: true, cert: '...', key: '...' }] }) or the same via contextOptions in the test config — any entry with noCertificate set to true that also sets cert, key, passphrase or pfx.","commonSituations":"Merging default client-certificate config with an override entry that adds noCertificate: true; copy-pasting a working cert entry and appending noCertificate to disable it instead of removing the fields; spreading config objects where cert fields leak into a noCertificate entry.","solutions":["Remove the cert, key, passphrase and pfx fields from the entry that has noCertificate: true.","If you actually want TLS client auth on the origin, delete noCertificate and keep the cert/key or pfx fields.","If you have multiple entries for the same origin, split them: one noCertificate-only entry, or one cert-carrying entry — not a hybrid."],"exampleFix":"// before\nclientCertificates: [{ origin: 'https://example.com', noCertificate: true, cert: './client.pem', key: './key.pem' }]\n// after\nclientCertificates: [{ origin: 'https://example.com', noCertificate: true }]","handlingStrategy":"validation","validationCode":"for (const c of clientCertificates) {\n  const fields = ['cert', 'key', 'passphrase', 'pfx'].filter(k => c[k] != null);\n  if (c.noCertificate && fields.length) throw new Error(`noCertificate entry has: ${fields.join(',')}`);\n  if (!c.origin) throw new Error('origin required');\n}","typeGuard":"function isNoCertOnlyEntry(c: { noCertificate?: boolean; cert?: string; key?: string; passphrase?: string; pfx?: Buffer }) {\n  return !!c.noCertificate && !c.cert && !c.key && !c.passphrase && !c.pfx;\n}","tryCatchPattern":"null","preventionTips":["Model noCertificate entries as a separate variant type in your config layer.","Deduplicate and normalize clientCertificates after merging configs from multiple sources."],"tags":["client-certificates","tls","browser-context","config-validation"],"backgroundTag":"conflicting-config-options","analyzedSha":"f1d33b5029be8bbc1095fe88e559117fa3a6243b","analyzedAt":"2026-09-15T07:37:15.003Z","contentChangedAt":"2026-09-15T07:37:15.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}