Server Behavior and Cookie Scenarios
This document explains the behavior of each server in the Cookie Playground infrastructure, including when and how cookies are handled.
Infrastructure Overview
The Cookie Playground consists of multiple servers, each serving different purposes:
- Main Domain:
cookie-playground.pun7o.click(parent domain) - Subdomain A:
site-a.cookie-playground.pun7o.click - Subdomain B:
site-b.cookie-playground.pun7o.click - Redirect Domain:
site-c.cookie-playground.pun7o.click(redirects to subdomain A) - Guide Domain:
guide.cookie-playground.pun7o.click(documentation server)
Server Architecture
Each server (except guide and redirect) follows the same pattern:
HTML Handler Lambda Function
Purpose: Serves HTML pages to browsers
Behavior:
- Reads HTML files from the
html/directory - Replaces domain placeholders (
{{DOMAIN}},{{PARENT_DOMAIN}}, etc.) with actual domain values - Returns HTML content with
Content-Type: text/html - Does NOT set any cookies via
Set-Cookieheaders
Endpoints:
GET /→ servesindex.htmlGET /index.html→ servesindex.htmlGET /cross-domain.html→ servescross-domain.html(subdomains A and B only)GET /parent-subdomain-test.html→ servesparent-subdomain-test.htmlGET /redirect-test.html→ servesredirect-test.html(subdomain A only)
Example Response:
HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
Cache-Control: no-cache, no-store, must-revalidate
<!DOCTYPE html>
<html>
<!-- HTML content with domain placeholders replaced -->
</html>
Pixel Handler Lambda Function
Purpose: Serves 1x1 transparent GIF pixels for tracking/testing
Behavior:
- Returns a 1x1 transparent GIF image
- Logs all request details to CloudWatch (including cookies received)
- Does NOT set any cookies via
Set-Cookieheaders - Includes CORS headers for cross-origin requests
Endpoints:
GET /pixel→ serves 1x1 transparent GIF- Supports query parameters (logged but not processed)
Example Response:
HTTP/1.1 200 OK
Content-Type: image/gif
Cache-Control: no-cache, no-store, must-revalidate
Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: GET, OPTIONS
[1x1 transparent GIF binary data]
Logging: The pixel handler logs the following information to CloudWatch:
- Timestamp
- HTTP method and path
- Query parameters
- Headers (User-Agent, Referer, Cookie)
- Request ID and source IP
Redirect Handler Lambda Function
Purpose: Performs HTTP 301 redirects to test cookie behavior during redirects
Behavior:
- Responds with
301 Permanent Redirectstatus - Redirects all requests to the configured target domain (default: subdomain A)
- Preserves path and query parameters
- Logs redirect details to CloudWatch
- Does NOT set any cookies via
Set-Cookieheaders
Endpoints:
GET /*→ redirects to target domain with same pathANY /*→ redirects to target domain with same path
Example Response:
HTTP/1.1 301 Moved Permanently
Location: https://site-a.cookie-playground.pun7o.click/path?query=value
Cache-Control: no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: 0
{"message": "Permanent redirect", "redirectTo": "https://..."}
Cookie Setting Mechanisms
Important: Servers Do NOT Automatically Set Cookies
Key Point: None of the server-side Lambda functions set cookies via Set-Cookie headers. This is intentional to allow users to experiment with cookie behavior using JavaScript.
Client-Side Cookie Setting (JavaScript)
Cookies are set using JavaScript in the HTML pages:
document.cookie = "name=value; Domain=.example.com; Path=/; Secure; SameSite=Lax";
When Cookies Are Set:
- User Interaction: When users interact with the cookie playground forms
- Page Load: Some pages may set cookies on load (via JavaScript)
- Pixel Requests: JavaScript can set cookies before loading pixels
Cookie Attributes Supported:
Domain: Specifies which domains can access the cookiePath: Specifies which paths can access the cookieSecure: Cookie only sent over HTTPSHttpOnly: Cookie cannot be accessed via JavaScript (must be set server-side)SameSite: Controls cross-site cookie behavior (None, Lax, Strict)Max-AgeorExpires: Controls cookie expiration
Server-Specific Behavior
Main Domain (cookie-playground.pun7o.click)
Available Pages:
/→ Main playground page/index.html→ Main playground page/parent-subdomain-test.html→ Parent-subdomain cookie testing
Domain Replacement:
{{DOMAIN}}→cookie-playground.pun7o.click{{SUBDOMAIN_A}}→site-a.cookie-playground.pun7o.click{{SUBDOMAIN_B}}→site-b.cookie-playground.pun7o.click{{GUIDE_DOMAIN}}→guide.cookie-playground.pun7o.click
Cookie Context:
- Cookies set with
Domain=cookie-playground.pun7o.clickare accessible by all subdomains - Cookies set with
Domain=.cookie-playground.pun7o.click(with leading dot) behave the same - Cookies set without Domain attribute are scoped to exact domain only
Subdomain A (site-a.cookie-playground.pun7o.click)
Available Pages:
/→ Subdomain A playground page/index.html→ Subdomain A playground page/cross-domain.html→ Cross-domain cookie testing/parent-subdomain-test.html→ Parent-subdomain cookie testing/redirect-test.html→ Redirect cookie testing
Domain Replacement:
{{DOMAIN}}→site-a.cookie-playground.pun7o.click{{PARENT_DOMAIN}}→cookie-playground.pun7o.click{{SUBDOMAIN_B}}→site-b.cookie-playground.pun7o.click{{GUIDE_DOMAIN}}→guide.cookie-playground.pun7o.click
Cookie Context:
- Cookies set with
Domain=cookie-playground.pun7o.clickare accessible by all subdomains - Cookies set with
Domain=site-a.cookie-playground.pun7o.clickare scoped to subdomain A only - Cookies set without Domain attribute are scoped to subdomain A only
Subdomain B (site-b.cookie-playground.pun7o.click)
Available Pages:
/→ Subdomain B playground page/index.html→ Subdomain B playground page/cross-domain.html→ Cross-domain cookie testing/parent-subdomain-test.html→ Parent-subdomain cookie testing
Domain Replacement:
{{DOMAIN}}→site-b.cookie-playground.pun7o.click{{PARENT_DOMAIN}}→cookie-playground.pun7o.click{{SUBDOMAIN_A}}→site-a.cookie-playground.pun7o.click{{GUIDE_DOMAIN}}→guide.cookie-playground.pun7o.click
Cookie Context:
- Cookies set with
Domain=cookie-playground.pun7o.clickare accessible by all subdomains - Cookies set with
Domain=site-b.cookie-playground.pun7o.clickare scoped to subdomain B only - Cookies set without Domain attribute are scoped to subdomain B only
Redirect Domain (site-c.cookie-playground.pun7o.click)
Behavior:
- All requests are redirected to
site-a.cookie-playground.pun7o.click(301 Permanent Redirect) - Path and query parameters are preserved
- Cookies are sent with redirect request if domain/path/SameSite conditions are met
Cookie Context:
- Cookies set on redirect domain are sent with redirect request
- Cookies can be set via JavaScript before redirect occurs
- Cookies set with
Domain=cookie-playground.pun7o.clickpersist after redirect
Cookie Scenarios
Scenario 1: First-Party Cookie on Main Domain
Setup:
- Visit
https://cookie-playground.pun7o.click - Set cookie:
test_cookie=value1; Domain=cookie-playground.pun7o.click; Path=/
Result:
- Cookie is accessible on main domain
- Cookie is accessible on all subdomains (a, b, redirect)
- Cookie is sent with all requests to these domains
Scenario 2: Subdomain-Specific Cookie
Setup:
- Visit
https://site-a.cookie-playground.pun7o.click - Set cookie:
subdomain_cookie=value2; Domain=site-a.cookie-playground.pun7o.click; Path=/
Result:
- Cookie is accessible on subdomain A only
- Cookie is NOT accessible on main domain or subdomain B
- Cookie is sent with requests to subdomain A
Scenario 3: Parent Domain Cookie from Subdomain
Setup:
- Visit
https://site-a.cookie-playground.pun7o.click - Set cookie:
parent_cookie=value3; Domain=cookie-playground.pun7o.click; Path=/
Result:
- Cookie is accessible on main domain
- Cookie is accessible on all subdomains (a, b, redirect)
- Cookie is sent with requests to all these domains
Scenario 4: Cross-Domain Pixel Request
Setup:
- Visit
https://site-a.cookie-playground.pun7o.click - Set cookie:
tracking_cookie=value4; Domain=cookie-playground.pun7o.click; Path=/ - Load pixel:
<img src="https://cookie-playground.pun7o.click/pixel?id=123" />
Result:
- Cookie is sent with pixel request (first-party context)
- Pixel handler receives cookie in
Cookieheader - Cookie is logged to CloudWatch
- No new cookies are set by pixel handler
Scenario 5: Third-Party Pixel Request
Setup:
- Visit
https://site-a.cookie-playground.pun7o.click - Set cookie:
third_party_cookie=value5; Domain=site-b.cookie-playground.pun7o.click; Path=/ - Load pixel from subdomain B:
<img src="https://site-b.cookie-playground.pun7o.click/pixel?id=123" />
Result:
- Cookie is sent with pixel request (third-party context)
- Pixel handler receives cookie in
Cookieheader - Cookie is logged to CloudWatch
- Cookie behavior depends on SameSite attribute
Scenario 6: Redirect with Cookies
Setup:
- Visit
https://site-c.cookie-playground.pun7o.click - Set cookie:
redirect_cookie=value6; Domain=cookie-playground.pun7o.click; Path=/ - Browser follows redirect to
site-a.cookie-playground.pun7o.click
Result:
- Cookie is sent with redirect request
- Cookie persists after redirect (if Domain matches)
- Cookie is accessible on target domain
Cookie Flow Diagrams
HTML Page Request Flow
Content-Type: text/html Note over Browser: HTML loaded, JavaScript executes Browser->>Browser Storage: document.cookie = name=value#59; Domain=example.com Browser Storage-->>Browser: Cookie stored
Pixel Request Flow
Cookie: tracking_cookie=value API Gateway->>Pixel Handler: Invoke Lambda Pixel Handler->>Pixel Handler: Extract request data Pixel Handler->>CloudWatch: Log request (including cookies) Pixel Handler->>API Gateway: Return 1x1 GIF (no Set-Cookie) API Gateway->>Browser: HTTP 200 OK
Content-Type: image/gif
Redirect Flow
Cookie: redirect_cookie=value API Gateway->>Redirect Handler: Invoke Lambda Redirect Handler->>Redirect Handler: Construct redirect URL Redirect Handler->>Redirect Handler: Log redirect details Redirect Handler->>API Gateway: HTTP 301
Location: target domain API Gateway->>Browser: HTTP 301 Moved Permanently Browser->>Target Server: GET /path
Cookie: redirect_cookie=value Target Server->>Browser: HTTP 200 OK
Testing Server Behavior
Inspecting Server Responses
Use browser developer tools to inspect HTTP responses:
- Open Developer Tools (F12)
- Navigate to Network tab
- Load a page (e.g.,
https://site-a.cookie-playground.pun7o.click) - Inspect Response Headers:
- Look for
Set-Cookieheaders (should be none) - Verify
Content-Typematches expected type - Check
Cache-Controlheaders
- Look for
Inspecting Pixel Requests
- Load a page with pixel tags
- Open Network tab in developer tools
- Filter by "pixel" or "gif"
- Inspect Request Headers:
- Check
Cookieheader (shows cookies sent) - Check
Refererheader (shows originating page)
- Check
- Inspect Response Headers:
- Verify
Content-Type: image/gif - Verify no
Set-Cookieheader
- Verify
Checking CloudWatch Logs
Pixel handlers log all requests to CloudWatch:
- Open AWS Console
- Navigate to CloudWatch Logs
- Find log group:
/aws/lambda/cookie-playground-pixel-handler-* - View log entries:
- Each pixel request logs full request details
- Includes cookies received in request
- Includes query parameters and headers
Summary
Key Points
- Servers do NOT set cookies automatically - This is intentional for experimentation
- Cookies are set via JavaScript - Using
document.cookiein HTML pages - Pixel handlers receive cookies - They log cookies but don't set them
- Redirect handlers preserve cookies - Cookies are sent with redirect requests
- Domain attribute controls scope - Parent domain cookies accessible by subdomains
When Cookies Are Added
- Via JavaScript: When users interact with playground forms
- Via JavaScript: When pages load (if JavaScript code sets cookies)
- Via JavaScript: Before pixel requests (if JavaScript sets cookies)
Which Cookies Are Set
- User-defined cookies: Set via playground forms with user-specified attributes
- Test cookies: Set via JavaScript examples in HTML pages
- No automatic cookies: Servers do not set cookies automatically
Cookie Receiving (Not Setting)
- Pixel handlers: Receive cookies in
Cookieheader, log them, but don't set new ones - HTML handlers: Receive cookies but don't process them
- Redirect handlers: Receive cookies and forward them with redirect
Next Steps
- Learn about Cookie Attributes to understand cookie behavior
- Explore Cross-Domain Behavior for cookie sharing scenarios
- Review HTTP Headers for Set-Cookie header details
- Test cookie scenarios using the Manual Testing Guide