Route bounded admin mutations through the existing administration dispatcher, covering apply, lifecycle, persistence, authorization, and result tracking. Add the browser controls, automatic result refresh, regression coverage, and phase documentation.
Cookie authentication and HTTPD adapter host checks
Run from the project root:
python3 tests/web_cookie_auth/run.py
Requires Python 3, a C11 compiler (cc), OpenSSL headers/libcrypto, and the pinned ESP-IDF source installation. The runner uses IDF_PATH when set, otherwise ~/.platformio/packages/framework-espidf. It writes only an automatically removed temporary directory. No network, device, pip/npm packages or server is needed. Do not disable C assertions.
The runner compiles production web_cookie_auth, web_session_store, web_auth_parse and web_httpd_adapter with bounded HTTPD/database/time/RNG doubles. It also executes the session-store public API suite. The installed IDF header getters, append-only response-header setter and right-aligned pending-data reader are extracted verbatim and compiled into the harness.
Coverage includes challenge reuse/consumption/expiry, capacities without eviction, global throttle, fragmented login bodies, secure cookie attributes and two simultaneous Set-Cookie fields, session-specific logout, duplicate fields/cookies, Origin/CSRF/method/Fetch Metadata rejection, Basic denial, currentness, stop/login and failure paths, six-header login budget, upgrade-state installation, and request cleanup preserving all 0–128 pending lengths through partial reads.
This is not the full IDF parser/dispatcher, real handshake/TLS/socket, browser, multicore task or hardware test. The private struct doubles do not prove binary layout; firmware compilation uses the actual pinned headers, and the version guard requires a new audit on SDK changes. Handshake sending and transport revocation are doubled. Actual on-wire pre-101 rejection, frame routing, pipelining/early bytes, cookie/CSP/browser recovery and loaded expiry latency remain M1 target gates. No sanitizer or runtime memory-reserve result is implied.
See docs/phase8d3_implementation.md for source verification, other suite commands, build accounting and the target checklist.
Read-only Serial Settings
python3 tests/web_cookie_auth/run.py --settings
Runs the existing auth/store suite plus five 8D.8 groups. Compiles exact extracted
production server handler/helpers, serial snapshot getter and enum formatters,
with the real cookie/store/parser/private adapter. Serial locking/state and HTTP
IO are doubled; authorization is not. Exercises normal-role/stale/expired/revoked
denial, DB failure, body/query/method/header/framing/Origin rejection before any
serial read, working values, zero-wait busy/uninitialized failure, no-store and
header/send errors. Adapter-only allocator substitution injects both staged
registration failures; the installed IDF unregister function frees successful
registration. No SDK files are modified. Lifecycle registration/optional failure
orchestration is separately tested by tests/web_admin_transport/server_lifecycle.py.
This does not run the full serial task/UART driver, TLS/network dispatcher or a real
browser. Target comparison with UART0 and runtime memory/stack validation remain
pending in docs/phase8d8_implementation.md; prior M2 signoff remains accepted.