Cookie Proof of Concept

Stage 0 test. Synthetic cookies only. Every run uses new random cookie names.

Build and environment
Frontend buildcookie-probe-frontend-v4-2026-10-09
Backend buildcookie-probe-backend-v4-2026-10-09
Backend is latest
PASS
Page originhttps://ctcsafefleet.com
Request URLhttps://ctcsafefleet.com/functions/cookieProbe
Same-origin request
YES
Path seen by server/run/e3e0d8f34db24c7b894d1e9dd165cb2c
Host seen by serverbase44-dispatcher-production.base44.workers.dev
document.cookie (JS-readable)

(empty)

A. Inspect legacy cookies

Read-only. Shows old-version cookies the server receives vs what this page can see.

B. Legacy cleanup + safety proof

Expires the 3 legacy names at Path=/ and Path=/functions. Proves a lookalike name, a decoy and all other cookies are untouched.

C. Create + expire (fresh names)

New random cookie names every run. HttpOnly vs visible, plus a 5-second expiry.

D. Logout A: 3 headers, one response

Fresh names. Sets 3 cookies, deletes all 3 in a single response, verifies each by exact name.

E. Logout B: 1 header per request

Same as D but each deletion is its own response.

F. Duplicate-path reproduction

Sets one name at Path=/functions then Path=/, deletes at Path=/ only, and shows the old copy survives.

G. Session cookie + revocation

Synthetic session: login, authenticate, logout, then try to reuse the cookie and a stolen copy of the token.

Test Summary

B. Legacy cleanup + safety proof
C. Create + expire (fresh names)
D. Logout A: 3 headers, one response
E. Logout B: 1 header per request
F. Duplicate-path reproduction
G. Session cookie + revocation