🍪

Cookie Testing Studio

Single Frontend • Multi-Backend API Cookie Synchronization Lab

Frontend: https://fa.apps.godainfotech.in
Architecture Setup (via Caddy Reverse Proxy)
💻
Frontend Client fa.apps.godainfotech.in HTTPS (Caddy Proxy)
CORS + Credentials
🌐
Backend 1 (NA) api-ba-na.apps.godainfotech.in HTTPS (Caddy Proxy)
🌍
Backend 2 (EU) api-ba-eu.apps.godainfotech.in HTTPS (Caddy Proxy)

1. Request Configuration

Fetch Client
Quick Select:
⚙️ Cookie Attributes & Scoping Options Configurable
Leave blank for host-only cookie, or set .apps.godainfotech.in for subdomain sharing

2. Live Response & Cookie Inspector

Ready Cookie: -
Responding Server -
Target Cookie Value -
Response Time -
Endpoint: No request made yet
Credentials Mode: credentials: 'include'
Response JSON Body
// Press "Set Cookie" or "Get Cookie" to execute API call...

3. Request & Cookie Transmission Log

Time Action Target Server HTTP Status Cookie Name Cookie Value Scoping / Details
No test requests executed yet. Click a button above to begin.

4. Cookie Mechanics & Troubleshooting Guide

🎯

Host-Only vs Subdomain Cookies

If Domain is omitted in Set-Cookie, the cookie is Host-Only: it will only be sent to the exact backend that issued it (e.g. api-ba-na).

If Domain=.apps.godainfotech.in is set, the browser shares the cookie with all subdomains (fa..., api-ba-na..., api-ba-eu...).

🔒

HttpOnly & Credentials

HttpOnly prevents JavaScript from reading the cookie via document.cookie (mitigating XSS).

To send/receive cookies in cross-origin fetch() requests, the client MUST include credentials: 'include'.

🛡️

CORS & Allowed Origins

When credentials: 'include' is used, the backend CANNOT use Access-Control-Allow-Origin: *.

The backend must explicitly reflect the requesting origin (e.g. https://fa.apps.godainfotech.in) and set Access-Control-Allow-Credentials: true.