# Cookie authentication and HTTPD adapter host checks Run from the project root: ```sh python3 tests/web_cookie_auth/run.py ``` Requires Python 3, a C11 compiler (`cc`), OpenSSL headers/libcrypto, and the pinned ESP-IDF source installation. The runner uses `IDF_PATH` when set, otherwise `~/.platformio/packages/framework-espidf`. It writes only an automatically removed temporary directory. No network, device, pip/npm packages or server is needed. Do not disable C assertions. The runner compiles production `web_cookie_auth`, `web_session_store`, `web_auth_parse` and `web_httpd_adapter` with bounded HTTPD/database/time/RNG doubles. It also executes the session-store public API suite. The installed IDF header getters, append-only response-header setter and right-aligned pending-data reader are extracted verbatim and compiled into the harness. Coverage includes challenge reuse/consumption/expiry, capacities without eviction, global throttle, fragmented login bodies, secure cookie attributes and two simultaneous Set-Cookie fields, session-specific logout, duplicate fields/cookies, Origin/CSRF/method/Fetch Metadata rejection, Basic denial, currentness, stop/login and failure paths, six-header login budget, upgrade-state installation, and request cleanup preserving all 0–128 pending lengths through partial reads. This is **not** the full IDF parser/dispatcher, real handshake/TLS/socket, browser, multicore task or hardware test. The private struct doubles do not prove binary layout; firmware compilation uses the actual pinned headers, and the version guard requires a new audit on SDK changes. Handshake sending and transport revocation are doubled. Actual on-wire pre-101 rejection, frame routing, pipelining/early bytes, cookie/CSP/browser recovery and loaded expiry latency remain M1 target gates. No sanitizer or runtime memory-reserve result is implied. See `docs/phase8d3_implementation.md` for source verification, other suite commands, build accounting and the target checklist. ## Read-only Serial Settings ```sh python3 tests/web_cookie_auth/run.py --settings ``` Runs the existing auth/store suite plus five 8D.8 groups. Compiles exact extracted production server handler/helpers, serial snapshot getter and enum formatters, with the real cookie/store/parser/private adapter. Serial locking/state and HTTP IO are doubled; authorization is not. Exercises normal-role/stale/expired/revoked denial, DB failure, body/query/method/header/framing/Origin rejection before any serial read, working values, zero-wait busy/uninitialized failure, no-store and header/send errors. Adapter-only allocator substitution injects both staged registration failures; the installed IDF unregister function frees successful registration. No SDK files are modified. Lifecycle registration/optional failure orchestration is separately tested by `tests/web_admin_transport/server_lifecycle.py`. This does not run the full serial task/UART driver, TLS/network dispatcher or a real browser. Target comparison with UART0 and runtime memory/stack validation remain pending in `docs/phase8d8_implementation.md`; prior M2 signoff remains accepted.