{"record":{"id":"c0f94006fa56ef54","repo":"evanw/esbuild","slug":"invalid-origin-s","errorCode":null,"errorMessage":"Invalid origin: %s","messagePattern":"Invalid origin: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"pkg/api/serve_other.go","lineNumber":787,"sourceCode":"\t\t\tserveOptions.Servedir = absPath\n\t\t} else {\n\t\t\treturn ServeResult{}, fmt.Errorf(\"Invalid serve path: %s\", serveOptions.Servedir)\n\t\t}\n\t}\n\n\t// Validate the \"fallback\" path\n\tif serveOptions.Fallback != \"\" {\n\t\tif absPath, ok := ctx.realFS.Abs(serveOptions.Fallback); ok {\n\t\t\tserveOptions.Fallback = absPath\n\t\t} else {\n\t\t\treturn ServeResult{}, fmt.Errorf(\"Invalid fallback path: %s\", serveOptions.Fallback)\n\t\t}\n\t}\n\n\t// Validate the CORS origins\n\tfor _, origin := range serveOptions.CORS.Origin {\n\t\tif star := strings.IndexByte(origin, '*'); star >= 0 && strings.ContainsRune(origin[star+1:], '*') {\n\t\t\treturn ServeResult{}, fmt.Errorf(\"Invalid origin: %s\", origin)\n\t\t}\n\t}\n\n\t// Stuff related to the output directory only matters if there are entry points\n\toutdirPathPrefix := \"\"\n\tif len(ctx.args.entryPoints) > 0 {\n\t\t// Don't allow serving when builds are written to stdout\n\t\tif ctx.args.options.WriteToStdout {\n\t\t\twhat := \"entry points\"\n\t\t\tif len(ctx.args.entryPoints) == 1 {\n\t\t\t\twhat = \"an entry point\"\n\t\t\t}\n\t\t\treturn ServeResult{}, fmt.Errorf(\"Cannot serve %s without an output path\", what)\n\t\t}\n\n\t\t// Compute the output path prefix\n\t\tif serveOptions.Servedir != \"\" && ctx.args.options.AbsOutputDir != \"\" {\n\t\t\t// Make sure the output directory is contained in the \"servedir\" directory","sourceCodeStart":769,"sourceCodeEnd":805,"githubUrl":"https://github.com/evanw/esbuild/blob/f6058f8364fe7ab91ca57a83e02577ed74c9cae4/pkg/api/serve_other.go#L769-L805","documentation":"Each CORS origin string in serve mode may contain at most one asterisk wildcard. This error fires when an origin contains two or more '*' characters, detected by finding a '*' and then another '*' in the remainder of the string. Multiple wildcards are not supported because they create ambiguous match patterns.","triggerScenarios":"Passing --cors-origin=https://*.*.example.com or the JS API equivalent with multiple asterisks in a single origin string.","commonSituations":"Misunderstanding CORS wildcard syntax and trying to match multiple subdomain levels with multiple wildcards (e.g. https://*.api.*.com).","solutions":["Use only one '*' wildcard per origin string","List multiple separate origins if you need to match different patterns","Use a single wildcard at the broadest level, e.g. 'https://*.example.com'"],"exampleFix":"// before\nesbuild.serve({ cors: { origin: ['https://*.*.example.com'] } })\n// after\nesbuild.serve({ cors: { origin: ['https://*.example.com', 'https://*.api.example.com'] } })","handlingStrategy":"validation","validationCode":"function validateCorsOrigins(origins) {\n  for (const origin of origins) {\n    const firstStar = origin.indexOf('*')\n    if (firstStar >= 0 && origin.indexOf('*', firstStar + 1) >= 0) {\n      throw new Error(`CORS origin has multiple wildcards: ${origin}`)\n    }\n  }\n}\nvalidateCorsOrigins(serveOptions.cors.origin || [])","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Use at most one '*' wildcard per CORS origin string","List multiple separate origin patterns instead of using multiple wildcards in one","Validate CORS origins against this rule before starting serve"],"tags":["esbuild","serve","cors","config"],"backgroundTag":null,"analyzedSha":"f6058f8364fe7ab91ca57a83e02577ed74c9cae4","analyzedAt":"2026-08-09T18:37:22.223Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}