Cookie authentication and HTTPD adapter host checks
Run from the project root:
python3 tests/web_cookie_auth/run.py
Requires Python 3, a C11 compiler (cc), OpenSSL headers/libcrypto, and the pinned ESP-IDF source installation. The runner uses IDF_PATH when set, otherwise ~/.platformio/packages/framework-espidf. It writes only an automatically removed temporary directory. No network, device, pip/npm packages or server is needed. Do not disable C assertions.
The runner compiles production web_cookie_auth, web_session_store, web_auth_parse and web_httpd_adapter with bounded HTTPD/database/time/RNG doubles. It also executes the session-store public API suite. The installed IDF header getters, append-only response-header setter and right-aligned pending-data reader are extracted verbatim and compiled into the harness.
Coverage includes challenge reuse/consumption/expiry, capacities without eviction, global throttle, fragmented login bodies, secure cookie attributes and two simultaneous Set-Cookie fields, session-specific logout, duplicate fields/cookies, Origin/CSRF/method/Fetch Metadata rejection, Basic denial, currentness, stop/login and failure paths, six-header login budget, upgrade-state installation, and request cleanup preserving all 0–128 pending lengths through partial reads.
This is not the full IDF parser/dispatcher, real handshake/TLS/socket, browser, multicore task or hardware test. The private struct doubles do not prove binary layout; firmware compilation uses the actual pinned headers, and the version guard requires a new audit on SDK changes. Handshake sending and transport revocation are doubled. Actual on-wire pre-101 rejection, frame routing, pipelining/early bytes, cookie/CSP/browser recovery and loaded expiry latency remain M1 target gates. No sanitizer or runtime memory-reserve result is implied.
See docs/phase8d3_implementation.md for source verification, other suite commands, build accounting and the target checklist.
Read-only Serial Settings
python3 tests/web_cookie_auth/run.py --settings
Runs the existing auth/store suite plus five 8D.8 groups. Compiles exact extracted
production server handler/helpers, serial snapshot getter and enum formatters,
with the real cookie/store/parser/private adapter. Serial locking/state and HTTP
IO are doubled; authorization is not. Exercises normal-role/stale/expired/revoked
denial, DB failure, body/query/method/header/framing/Origin rejection before any
serial read, working values, zero-wait busy/uninitialized failure, no-store and
header/send errors. Adapter-only allocator substitution injects both staged
registration failures; the installed IDF unregister function frees successful
registration. No SDK files are modified. Lifecycle registration/optional failure
orchestration is separately tested by tests/web_admin_transport/server_lifecycle.py.
This does not run the full serial task/UART driver, TLS/network dispatcher or a real
browser. Target comparison with UART0 and runtime memory/stack validation remain
pending in docs/phase8d8_implementation.md; prior M2 signoff remains accepted.