Manual Testing Guide

Step-by-step procedures for manually testing cookie behavior in the playground.

Prerequisites

  1. Infrastructure deployed (see main README.md)
  2. Access to playground domains
  3. Browser with Developer Tools (F12)
  4. Understanding of basic cookie concepts

Testing Setup

Browser Preparation

  1. Clear Browser Data:

    • Clear cookies and cache
    • Use Incognito/Private mode for clean testing
    • Or use regular mode and clear cookies manually
  2. Open Developer Tools:

    • Press F12 or right-click → Inspect
    • Go to Network tab
    • Go to Application/Storage tab → Cookies
  3. Enable Cookie Inspection:

    • Check "Preserve log" in Network tab
    • Enable cookie viewing in Application tab

Test Scenarios

Objective: Set and read a simple cookie

Steps:

  1. Visit https://cookie-playground.pun7o.click
  2. Fill in cookie form:
    • Name: test_cookie
    • Value: test_value_123
    • Leave Domain empty (uses current domain)
    • Path: /
    • SameSite: Leave default
  3. Click "Set Cookie"
  4. Click "Read All Cookies"
  5. Verify cookie appears in cookie display

Expected Result:

Check HTTP Inspector:

Objective: Test how Domain attribute affects cookie accessibility

Part A - Current Domain Only:

  1. Visit https://site-a.cookie-playground.pun7o.click
  2. Set cookie:
    • Name: subdomain_only
    • Value: value_a
    • Domain: Leave empty (current domain)
    • Path: /
  3. Click "Set Cookie"
  4. Navigate to https://cookie-playground.pun7o.click
  5. Click "Read All Cookies"

Expected Result: Cookie NOT visible on parent domain

Part B - Parent Domain:

  1. Return to https://site-a.cookie-playground.pun7o.click
  2. Set cookie:
    • Name: shared_cookie
    • Value: shared_value
    • Domain: cookie-playground.pun7o.click
    • Path: /
  3. Click "Set Cookie"
  4. Navigate to https://cookie-playground.pun7o.click
  5. Click "Read All Cookies"

Expected Result: Cookie visible on parent domain

Test 3: SameSite Attribute Testing

Objective: Test SameSite behavior

Setup: Use two playground domains

Steps:

  1. Visit https://cookie-playground.pun7o.click
  2. Set cookie:
    • Name: samesite_test
    • Value: strict_value
    • SameSite: Strict
    • Secure: Checked
  3. Click "Set Cookie"
  4. Open new tab and visit https://site-a.cookie-playground.pun7o.click
  5. In that tab, load pixel: <img src="https://cookie-playground.pun7o.click/pixel">
  6. Check Network tab - does the Cookie header include samesite_test?

Expected Result:

Test 4: Secure Flag Testing

Objective: Verify Secure flag behavior

Steps:

  1. Visit https://cookie-playground.pun7o.click (HTTPS)
  2. Set cookie:
    • Name: secure_test
    • Value: secure_value
    • Secure: Checked
  3. Click "Set Cookie"
  4. Check Application tab → Cookies
  5. Verify cookie is stored

Expected Result: Cookie stored and sent with HTTPS requests

Note: Secure flag required for HTTPS sites in production

Objective: Test Max-Age attribute

Steps:

  1. Visit https://cookie-playground.pun7o.click
  2. Set cookie:
    • Name: expiring_cookie
    • Value: will_expire
    • Max-Age: 60 (1 minute)
    • Path: /
  3. Click "Set Cookie"
  4. Read cookies immediately - should see cookie
  5. Wait 1 minute
  6. Read cookies again - cookie should be gone

Expected Result: Cookie expires after specified time

Alternative: Set Max-Age to 3600 (1 hour) and verify it persists

Test 6: Path Attribute Testing

Objective: Test Path restriction

Steps:

  1. Visit https://cookie-playground.pun7o.click
  2. Set cookie:
    • Name: path_cookie
    • Value: path_value
    • Path: /test
  3. Click "Set Cookie"
  4. Navigate to https://cookie-playground.pun7o.click/test (if page exists)
  5. Check cookies - should see path_cookie
  6. Navigate to https://cookie-playground.pun7o.click (root)
  7. Check cookies - cookie may not appear (depends on browser)

Expected Result: Cookie only sent with requests matching path

Objective: Test parent domain cookie access by subdomains

Steps:

  1. Visit https://cookie-playground.pun7o.click/parent-subdomain-test.html
  2. Click "Set Cookie with Domain=cookie-playground.pun7o.click"
  3. Note the cookie in the display
  4. Navigate to https://site-a.cookie-playground.pun7o.click/parent-subdomain-test.html
  5. Click "Read Cookies"
  6. Verify parent domain cookie is visible

Expected Result:

Objective: Test that parent cannot access subdomain cookie

Steps:

  1. Visit https://site-a.cookie-playground.pun7o.click/parent-subdomain-test.html
  2. Click "Set Cookie with Domain=site-a.cookie-playground.pun7o.click"
  3. Note the cookie
  4. Navigate to https://cookie-playground.pun7o.click/parent-subdomain-test.html
  5. Click "Read Cookies"
  6. Verify subdomain cookie is NOT visible

Expected Result: Parent domain cannot see subdomain-specific cookie

Test 9: Pixel Tracking Test

Objective: Test pixel endpoint and logging

Steps:

  1. Visit https://cookie-playground.pun7o.click
  2. Set a cookie: tracking_id=user123
  3. Load pixel: <img src="https://cookie-playground.pun7o.click/pixel?id=123&event=page_view">
  4. Check HTTP inspector for pixel request
  5. Verify pixel returns 200 status
  6. Check CloudWatch logs (AWS Console) for pixel data

Expected Result:

Test 10: Cross-Domain Pixel

Objective: Test pixel from different domain

Steps:

  1. Visit https://site-a.cookie-playground.pun7o.click
  2. Set cookie: user_segment=premium
  3. Load pixel from parent: <img src="https://cookie-playground.pun7o.click/pixel?source=a&segment=premium">
  4. Check Network tab
  5. Inspect request headers
  6. Verify cookie behavior

Expected Result:

Objective: Test cookie behavior with 301 redirects

Steps:

  1. Visit https://site-c.cookie-playground.pun7o.click
  2. Observe redirect to https://site-a.cookie-playground.pun7o.click
  3. Check Network tab for redirect flow:
    • Initial request to redirect domain
    • 301 response with Location header
    • Follow-up request to target domain
  4. Visit https://site-a.cookie-playground.pun7o.click/redirect-test.html
  5. Use "Follow Redirect Programmatically" button
  6. Observe HTTP inspector output

Expected Result:

Test 12: HTTP Inspector Verification

Objective: Verify HTTP request/response details

Steps:

  1. Visit any playground page
  2. Set a cookie using the form
  3. Observe HTTP inspector panel
  4. Verify you see:
    • Status code (200)
    • Set-Cookie header with full attributes
    • Request URL
  5. Click "Read Cookies"
  6. Verify Cookie header appears in inspector

Expected Result: All HTTP details visible in inspector

Testing Checklist

Use this checklist for systematic testing:

Common Test Patterns

Pattern 1: Fresh Start Testing

1. Open Incognito/Private window
2. Visit playground domain
3. Perform test
4. Close window
5. Repeat with fresh session
1. Set multiple cookies with different attributes
2. Navigate between domains
3. Verify which cookies are accessible
4. Document results

Pattern 3: Cross-Browser Testing

1. Test in Chrome
2. Test in Firefox
3. Test in Safari
4. Compare behavior differences

Interpreting Results

Expected Behaviors

Cookie Set Successfully:

Cookie Accessible:

Cookie Blocked:

Unexpected Behaviors

Cookie Not Set:

Cookie Not Accessible:

Documentation

Document Your Findings:

  1. Screenshot HTTP inspector output
  2. Note browser and version
  3. Record cookie attributes used
  4. Document expected vs actual behavior

Troubleshooting Tests

If tests don't work as expected:

  1. Clear Browser State: Start fresh
  2. Check Browser Settings: Privacy/security settings may block cookies
  3. Verify Infrastructure: Ensure resources deployed correctly
  4. Check Console Errors: Browser DevTools console
  5. Review HTTP Headers: Verify headers in Network tab
  6. Check CloudWatch Logs: For pixel endpoint issues

Advanced Testing

  1. Set 10+ cookies on same domain
  2. Verify all cookies work
  3. Try setting 50+ cookies
  4. Observe browser behavior
  1. Set cookie with large value (1000+ characters)
  2. Verify cookie is set
  3. Try very large value (4000+ characters)
  4. Observe browser limits

Test Concurrent Cookies

  1. Set multiple cookies simultaneously
  2. Verify all are stored
  3. Read all cookies
  4. Verify all accessible

Next Steps