Source
From PR #65 review follow-up: #65 (comment)
Context
Cx3 legacy item: PR #65 e2e uses a plain gocell_rt cookie because localhost over plain HTTP cannot set the real __Host-gocell_rt cookie (Secure + __Host- constraints). The test comment documents the limitation, but fidelity is lower than production cookie behavior.
Desired direction
Introduce an HTTPS-capable dev/e2e proxy or equivalent test harness so auth e2e can exercise the real __Host-gocell_rt cookie shape.
Acceptance
- Auth cold-start e2e can run against HTTPS locally/CI.
- The test uses
__Host-gocell_rt with Secure-compatible behavior instead of the plain fallback name.
- Existing no-cookie and cookie-refresh scenarios remain covered.
Source
From PR #65 review follow-up: #65 (comment)
Context
Cx3 legacy item: PR #65 e2e uses a plain
gocell_rtcookie because localhost over plain HTTP cannot set the real__Host-gocell_rtcookie (Secure+__Host-constraints). The test comment documents the limitation, but fidelity is lower than production cookie behavior.Desired direction
Introduce an HTTPS-capable dev/e2e proxy or equivalent test harness so auth e2e can exercise the real
__Host-gocell_rtcookie shape.Acceptance
__Host-gocell_rtwith Secure-compatible behavior instead of the plain fallback name.