Factory.ai

AI Coding Agents

Security

Session cookie tests for coding agent changes

September 29, 2026 - 2 minute read

Session cookie testing checks how an application creates, sends, rotates, and removes browser session state. A coding agent change to authentication middleware or host routing can leave the main sign-in flow working while widening cookie scope, weakening transport settings, or failing to end a session.

RFC 6265 defines the Cookie and Set-Cookie fields, including domain, path, expiration, Secure, and HttpOnly behavior. Tests should inspect the attributes sent by the server and the browser behavior they produce.

Record the cookie name, host or domain scope, path, lifetime, and required attributes. Include every application host that participates in authentication. A domain-wide cookie may reach sibling services that do not need it, while an overly narrow path can create duplicate cookies with the same name.

Separate session cookies from preferences and anonymous identifiers. Only the credentials that authorize requests need the strict session lifecycle. Tests become clearer when they assert each cookie’s purpose instead of scanning for one expected header.

Use an isolated test account and capture the state before sign-in, after sign-in, after privilege changes, and after logout.

Test creation, rotation, and expiration

Confirm that an authenticated response sets the expected Secure and HttpOnly attributes. Secure limits transport to protected connections. HttpOnly keeps the cookie out of script-readable APIs, but the browser still sends it with requests.

Exercise session fixation defenses by supplying a pre-authentication session, signing in, and confirming that the authenticated session identifier changes. Repeat the check after a privilege elevation or other event that the application treats as security-sensitive.

Test both idle and absolute expiration if the application promises them. Use a controllable clock where possible. A test that waits in real time is slow and can hide differences between server-side expiration and the browser cookie’s lifetime.

Logout should invalidate the server-side session and expire the browser cookie. Replay the old value against a protected endpoint and confirm denial. Repeat from another browser context when the product supports multiple active sessions.

Give a coding agent a safe authentication task

Provide the intended cookie contract, affected hosts, protected route, and focused test commands. Require evidence from actual response headers and a browser context. Unit tests around a cookie utility cannot show how middleware, proxies, and host routing combine.

Factory’s Automated Code Review can apply repository guidance to authentication changes. A review rule can flag modified cookie attributes, session rotation, or logout handling when corresponding tests are absent.

Never place a real session token in a task, fixture, screenshot, or build log. Generate short-lived synthetic values inside the isolated test.

Record attribute names and lifecycle outcomes without recording cookie values. Verify behavior on redirects, error pages, and alternate hosts because those paths can set or clear cookies differently.

Pair cookie tests with server-side authorization tests. A correctly scoped cookie still represents a session that the application must validate for every protected action.

Run the same checks after framework, proxy, or identity-provider upgrades because defaults can change outside authentication code.

Further reading

Ready to build the software of the future?

Start building

Arrow Right Icon