Skip to content

fix(client-certificates): reestablish a way to explicitly send no client certificate for an origin - #42547

Merged
Pavel Feldman (pavelfeldman) merged 3 commits into
microsoft:mainfrom
egfx-notifications:fix-42546
Sep 10, 2026
Merged

Pavel Feldman (pavelfeldman) merged 3 commits into
microsoft:mainfrom
egfx-notifications:fix-42546

Conversation

@egfx-notifications

Copy link
Copy Markdown
Contributor

Summary

Restores the ability to explicitly send no client certificate for an origin, fixing a regression from #41113 (first released in v1.61.0).

Details

  • Adds a new sendNone option to the clientCertificates test option so we can explicitly request sending no certificate to a server rather than relying on the previous implicit "clientCertificates set, but origin not mentioned in configured origins means intercept and send no certificate"
  • Adds tests to prevent a future silent regression and clarifies the docs.

Fixes #42546

…rage

sendNone combined with cert/key/passphrase/pfx, or mixed with a real
certificate on the same origin, now throws instead of silently
resolving. Adds test coverage for sendNone across fetch, browser and
persistentContext, and clarifies the docs.
Comment thread docs/src/api/params.md Outdated
- `pfxPath` ?<[path]> Path to the PFX or PKCS12 encoded private key and certificate chain.
- `pfx` ?<[Buffer]> Direct value of the PFX or PKCS12 encoded private key and certificate chain.
- `passphrase` ?<[string]> Passphrase for the private key (PEM or PFX).
- `sendNone` ?<[boolean]> Explicitly send no client certificate for this origin. Must be the only field set besides `origin`.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The name reads oddly next to the other options, how about noCertificate?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds good, I'll update that to noCertificate

@github-actions

This comment has been minimized.

@github-actions

This comment has been minimized.

@yury-s Yury Semikhatsky (yury-s) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please do the rename and accept CLA so that we could merge the PR.

@egfx-notifications

Copy link
Copy Markdown
Contributor Author

@microsoft-github-policy-service agree company="Seven.One Production GmbH"

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "tests 1"

11 flaky ⚠️ [chromium-library] › library/browsercontext-page-event.spec.ts:173 › should work with Ctrl-clicking `@frozen-time-library-chromium-linux`
⚠️ [chromium-library] › library/video.spec.ts:664 › screencast › should capture full viewport `@chromium-ubuntu-22.04-arm-node20`
⚠️ [chromium-library] › library/video.spec.ts:736 › screencast › should work with video+trace `@chromium-ubuntu-22.04-arm-node20`
⚠️ [chromium-library] › library/chromium/chromium.spec.ts:373 › should produce network events, routing, and annotations for Service Worker `@chromium-ubuntu-22.04-node24`
⚠️ [chromium-library] › library/popup.spec.ts:260 › should not throw when click closes popup `@chromium-ubuntu-22.04-node24`
⚠️ [chromium-library] › library/trace-viewer-scrub.spec.ts:177 › should drag scrubber to select action `@chromium-ubuntu-22.04-node20`
⚠️ [chromium-library] › library/video.spec.ts:664 › screencast › should capture full viewport `@chromium-ubuntu-22.04-node20`
⚠️ [firefox-library] › library/browsercontext-cookies-third-party.spec.ts:257 › third party 'Partitioned;' cookies `@firefox-ubuntu-22.04-node20`
⚠️ [firefox-library] › library/browsercontext-cookies-third-party.spec.ts:470 › top level 'Partitioned;' cookie and same origin iframe `@firefox-ubuntu-22.04-node20`
⚠️ [firefox-page] › page/page-event-request.spec.ts:181 › should return response body when Cross-Origin-Opener-Policy is set `@firefox-ubuntu-22.04-node20`
⚠️ [playwright-test] › ui-mode-trace.spec.ts:827 › should update state on subsequent run `@windows-latest-node22`

51569 passed, 1247 skipped


Merge workflow run.

@github-actions

Copy link
Copy Markdown
Contributor

Test results for "MCP"

1 failed
❌ [webkit] › mcp/http.spec.ts:105 › http transport browser lifecycle (isolated) @mcp-ubuntu-latest-webkit

8347 passed, 1376 skipped


Merge workflow run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Explicitly sending no client certificates broken since v1.61.0

3 participants