Manual Testing Guide
Step-by-step procedures for manually testing cookie behavior in the playground.
Prerequisites
- Infrastructure deployed (see main README.md)
- Access to playground domains
- Browser with Developer Tools (F12)
- Understanding of basic cookie concepts
Testing Setup
Browser Preparation
Clear Browser Data:
- Clear cookies and cache
- Use Incognito/Private mode for clean testing
- Or use regular mode and clear cookies manually
Open Developer Tools:
- Press F12 or right-click → Inspect
- Go to Network tab
- Go to Application/Storage tab → Cookies
Enable Cookie Inspection:
- Check "Preserve log" in Network tab
- Enable cookie viewing in Application tab
Test Scenarios
Test 1: Basic Cookie Setting and Reading
Objective: Set and read a simple cookie
Steps:
- Visit
https://cookie-playground.pun7o.click - Fill in cookie form:
- Name:
test_cookie - Value:
test_value_123 - Leave Domain empty (uses current domain)
- Path:
/ - SameSite: Leave default
- Name:
- Click "Set Cookie"
- Click "Read All Cookies"
- Verify cookie appears in cookie display
Expected Result:
- Cookie
test_cookie=test_value_123visible - Cookie accessible via JavaScript
Check HTTP Inspector:
- Should show
Set-Cookie: test_cookie=test_value_123; Path=/ - Status code: 200
Test 2: Cookie Domain Attribute
Objective: Test how Domain attribute affects cookie accessibility
Part A - Current Domain Only:
- Visit
https://site-a.cookie-playground.pun7o.click - Set cookie:
- Name:
subdomain_only - Value:
value_a - Domain: Leave empty (current domain)
- Path:
/
- Name:
- Click "Set Cookie"
- Navigate to
https://cookie-playground.pun7o.click - Click "Read All Cookies"
Expected Result: Cookie NOT visible on parent domain
Part B - Parent Domain:
- Return to
https://site-a.cookie-playground.pun7o.click - Set cookie:
- Name:
shared_cookie - Value:
shared_value - Domain:
cookie-playground.pun7o.click - Path:
/
- Name:
- Click "Set Cookie"
- Navigate to
https://cookie-playground.pun7o.click - Click "Read All Cookies"
Expected Result: Cookie visible on parent domain
Test 3: SameSite Attribute Testing
Objective: Test SameSite behavior
Setup: Use two playground domains
Steps:
- Visit
https://cookie-playground.pun7o.click - Set cookie:
- Name:
samesite_test - Value:
strict_value - SameSite:
Strict - Secure: Checked
- Name:
- Click "Set Cookie"
- Open new tab and visit
https://site-a.cookie-playground.pun7o.click - In that tab, load pixel:
<img src="https://cookie-playground.pun7o.click/pixel"> - Check Network tab - does the Cookie header include
samesite_test?
Expected Result:
- Cookie NOT sent with cross-domain pixel request (SameSite=Strict)
- Try with SameSite=Lax - should work for top-level navigation
Test 4: Secure Flag Testing
Objective: Verify Secure flag behavior
Steps:
- Visit
https://cookie-playground.pun7o.click(HTTPS) - Set cookie:
- Name:
secure_test - Value:
secure_value - Secure: Checked
- Name:
- Click "Set Cookie"
- Check Application tab → Cookies
- Verify cookie is stored
Expected Result: Cookie stored and sent with HTTPS requests
Note: Secure flag required for HTTPS sites in production
Test 5: Cookie Expiration
Objective: Test Max-Age attribute
Steps:
- Visit
https://cookie-playground.pun7o.click - Set cookie:
- Name:
expiring_cookie - Value:
will_expire - Max-Age:
60(1 minute) - Path:
/
- Name:
- Click "Set Cookie"
- Read cookies immediately - should see cookie
- Wait 1 minute
- Read cookies again - cookie should be gone
Expected Result: Cookie expires after specified time
Alternative: Set Max-Age to 3600 (1 hour) and verify it persists
Test 6: Path Attribute Testing
Objective: Test Path restriction
Steps:
- Visit
https://cookie-playground.pun7o.click - Set cookie:
- Name:
path_cookie - Value:
path_value - Path:
/test
- Name:
- Click "Set Cookie"
- Navigate to
https://cookie-playground.pun7o.click/test(if page exists) - Check cookies - should see path_cookie
- Navigate to
https://cookie-playground.pun7o.click(root) - Check cookies - cookie may not appear (depends on browser)
Expected Result: Cookie only sent with requests matching path
Test 7: Parent-Subdomain Cookie Sharing
Objective: Test parent domain cookie access by subdomains
Steps:
- Visit
https://cookie-playground.pun7o.click/parent-subdomain-test.html - Click "Set Cookie with Domain=cookie-playground.pun7o.click"
- Note the cookie in the display
- Navigate to
https://site-a.cookie-playground.pun7o.click/parent-subdomain-test.html - Click "Read Cookies"
- Verify parent domain cookie is visible
Expected Result:
- Subdomain A can see parent domain cookie
- Parent domain cookie accessible by all subdomains
Test 8: Subdomain-Specific Cookie
Objective: Test that parent cannot access subdomain cookie
Steps:
- Visit
https://site-a.cookie-playground.pun7o.click/parent-subdomain-test.html - Click "Set Cookie with Domain=site-a.cookie-playground.pun7o.click"
- Note the cookie
- Navigate to
https://cookie-playground.pun7o.click/parent-subdomain-test.html - Click "Read Cookies"
- Verify subdomain cookie is NOT visible
Expected Result: Parent domain cannot see subdomain-specific cookie
Test 9: Pixel Tracking Test
Objective: Test pixel endpoint and logging
Steps:
- Visit
https://cookie-playground.pun7o.click - Set a cookie:
tracking_id=user123 - Load pixel:
<img src="https://cookie-playground.pun7o.click/pixel?id=123&event=page_view"> - Check HTTP inspector for pixel request
- Verify pixel returns 200 status
- Check CloudWatch logs (AWS Console) for pixel data
Expected Result:
- Pixel loads (1x1 GIF)
- Request logged to CloudWatch
- Cookie sent with pixel request (if Domain/Path match)
Test 10: Cross-Domain Pixel
Objective: Test pixel from different domain
Steps:
- Visit
https://site-a.cookie-playground.pun7o.click - Set cookie:
user_segment=premium - Load pixel from parent:
<img src="https://cookie-playground.pun7o.click/pixel?source=a&segment=premium"> - Check Network tab
- Inspect request headers
- Verify cookie behavior
Expected Result:
- Pixel loads successfully
- Cookie behavior depends on Domain attribute and SameSite policy
- Request logged to CloudWatch
Test 11: Redirect Cookie Test
Objective: Test cookie behavior with 301 redirects
Steps:
- Visit
https://site-c.cookie-playground.pun7o.click - Observe redirect to
https://site-a.cookie-playground.pun7o.click - Check Network tab for redirect flow:
- Initial request to redirect domain
- 301 response with Location header
- Follow-up request to target domain
- Visit
https://site-a.cookie-playground.pun7o.click/redirect-test.html - Use "Follow Redirect Programmatically" button
- Observe HTTP inspector output
Expected Result:
- Redirect works (301 status)
- Location header shows target domain
- Cookie behavior depends on SameSite policy
Test 12: HTTP Inspector Verification
Objective: Verify HTTP request/response details
Steps:
- Visit any playground page
- Set a cookie using the form
- Observe HTTP inspector panel
- Verify you see:
- Status code (200)
- Set-Cookie header with full attributes
- Request URL
- Click "Read Cookies"
- Verify Cookie header appears in inspector
Expected Result: All HTTP details visible in inspector
Testing Checklist
Use this checklist for systematic testing:
- Basic cookie set/read works
- Domain attribute affects accessibility
- Path attribute restricts cookie scope
- SameSite=Strict blocks cross-site requests
- SameSite=Lax allows top-level navigation
- Secure flag required for HTTPS
- Max-Age expiration works
- Parent domain cookies accessible by subdomains
- Subdomain cookies NOT accessible by parent
- Pixel endpoint logs to CloudWatch
- Redirect preserves cookies (when SameSite allows)
- HTTP inspector shows correct headers
- Multiple cookies work simultaneously
- Cookie deletion works
- Clear all cookies function works
Common Test Patterns
Pattern 1: Fresh Start Testing
1. Open Incognito/Private window
2. Visit playground domain
3. Perform test
4. Close window
5. Repeat with fresh session
Pattern 2: Cookie State Testing
1. Set multiple cookies with different attributes
2. Navigate between domains
3. Verify which cookies are accessible
4. Document results
Pattern 3: Cross-Browser Testing
1. Test in Chrome
2. Test in Firefox
3. Test in Safari
4. Compare behavior differences
Interpreting Results
Expected Behaviors
Cookie Set Successfully:
- Appears in cookie display
- Set-Cookie header in HTTP inspector
- Status 200
Cookie Accessible:
- Visible in "Read Cookies" display
- Cookie header sent with requests
- Accessible via
document.cookie(if not HttpOnly)
Cookie Blocked:
- Not sent with cross-site requests (SameSite policy)
- Not accessible by different domain (Domain mismatch)
- Not sent with sub-resource requests (SameSite=Lax)
Unexpected Behaviors
Cookie Not Set:
- Check browser console for errors
- Verify Secure flag not required on HTTP
- Check cookie size limits
- Verify domain format
Cookie Not Accessible:
- Check Domain attribute
- Verify Path matches request path
- Check cookie expiration
- Verify browser privacy settings
Documentation
Document Your Findings:
- Screenshot HTTP inspector output
- Note browser and version
- Record cookie attributes used
- Document expected vs actual behavior
Troubleshooting Tests
If tests don't work as expected:
- Clear Browser State: Start fresh
- Check Browser Settings: Privacy/security settings may block cookies
- Verify Infrastructure: Ensure resources deployed correctly
- Check Console Errors: Browser DevTools console
- Review HTTP Headers: Verify headers in Network tab
- Check CloudWatch Logs: For pixel endpoint issues
Advanced Testing
Test Cookie Limits
- Set 10+ cookies on same domain
- Verify all cookies work
- Try setting 50+ cookies
- Observe browser behavior
Test Cookie Size
- Set cookie with large value (1000+ characters)
- Verify cookie is set
- Try very large value (4000+ characters)
- Observe browser limits
Test Concurrent Cookies
- Set multiple cookies simultaneously
- Verify all are stored
- Read all cookies
- Verify all accessible
Related Topics
- Using the Playground - Infrastructure usage
- HTTP Inspection - Understanding HTTP details
- Troubleshooting - Common issues
Next Steps
- Run through all test scenarios
- Document your findings
- Explore HTTP Inspection for deeper analysis
- Review Browser Behaviors for browser differences