← Files 한결 개인 도구함ARCHIVED FILE

skills/playwright-cli/references/storage-state.md

4.83 KB · Sep 30, 2026 · 23:15 UTC

↓ Download file

# Synthetic Storage-State Testing

Manage cookies, localStorage, sessionStorage, and saved browser state only in a newly created disposable test profile containing synthetic values. Never inspect, list, export, copy, persist, or restore a user's real signed-in browser state, cookies, passwords, tokens, account identifiers, or existing profile.

## Preconditions

Continue only when all of these are true:

- the user requested a storage-specific test;
- the session and profile were created for this test and have never signed in to a real account;
- the origin is a local fixture or an explicitly synthetic `.invalid` placeholder;
- every value is visibly synthetic and begins with `TEST_` where practical;
- the state file is in a task-specific temporary directory outside the plugin, repository, and public outputs.

If any condition is uncertain, use an in-memory session without storage inspection. For profile isolation, read [session-management.md](session-management.md).

## Save and restore one synthetic state

```bash
# Use only after creating synthetic values in the isolated test profile
playwright-cli state-save TEST_SYNTHETIC_STATE.json

# Restore only into another disposable synthetic test session
playwright-cli state-load TEST_SYNTHETIC_STATE.json
playwright-cli open https://example.invalid
```

Never save a state after real authentication. A state file must not be used to transfer login access between sessions, machines, accounts, tools, or people.

## Synthetic state shape

This redacted shape illustrates the fields without supplying real authentication data:

```json
{
  "cookies": [
    {
      "name": "TEST_COOKIE_NAME",
      "value": "TEST_COOKIE_VALUE",
      "domain": "example.invalid",
      "path": "/",
      "expires": 1893456000,
      "httpOnly": true,
      "secure": true,
      "sameSite": "Lax"
    }
  ],
  "origins": [
    {
      "origin": "https://example.invalid",
      "localStorage": [
        { "name": "TEST_THEME", "value": "TEST_DARK" },
        { "name": "TEST_USER", "value": "TEST_USER_VALUE" }
      ]
    }
  ]
}
```

## Synthetic cookies

Create and remove only cookie names generated for the same disposable test. Do not list or retrieve cookies from any pre-existing profile.

```bash
playwright-cli cookie-set TEST_COOKIE_NAME TEST_COOKIE_VALUE --domain=example.invalid --path=/ --httpOnly --secure --sameSite=Lax
playwright-cli cookie-delete TEST_COOKIE_NAME
```

For multiple synthetic cookies:

```bash
playwright-cli run-code "async page => {
  await page.context().addCookies([
    { name: 'TEST_SESSION', value: 'TEST_SESSION_VALUE', domain: 'example.invalid', path: '/', httpOnly: true },
    { name: 'TEST_PREFERENCE', value: 'TEST_DARK', domain: 'example.invalid', path: '/' }
  ]);
}"
```

## Synthetic localStorage

Operate only on explicit `TEST_` keys created by the current test. Avoid `localstorage-list` and broad exports because they can reveal unrelated data. Use `localstorage-clear` only in a confirmed empty disposable profile.

```bash
playwright-cli localstorage-set TEST_THEME TEST_DARK
playwright-cli localstorage-get TEST_THEME
playwright-cli localstorage-delete TEST_THEME
```

For several explicit synthetic values:

```bash
playwright-cli run-code "async page => {
  await page.evaluate(() => {
    localStorage.setItem('TEST_THEME', 'TEST_DARK');
    localStorage.setItem('TEST_USER', 'TEST_USER_VALUE');
    localStorage.setItem('TEST_EXPIRY', String(Date.now() + 3600000));
  });
}"
```

## Synthetic sessionStorage

Use exact keys generated for the current test. Do not list or export all sessionStorage values.

```bash
playwright-cli sessionstorage-set TEST_STEP TEST_3
playwright-cli sessionstorage-get TEST_STEP
playwright-cli sessionstorage-delete TEST_STEP
```

## Roundtrip example

```bash
# Step 1: create one synthetic preference on a synthetic origin
playwright-cli open https://example.invalid
playwright-cli localstorage-set TEST_THEME TEST_DARK
playwright-cli state-save TEST_SYNTHETIC_STATE.json

# Step 2: restore only in a new disposable synthetic session
playwright-cli state-load TEST_SYNTHETIC_STATE.json
playwright-cli open https://example.invalid
playwright-cli localstorage-get TEST_THEME
```

This tests serialization only; it does not represent authentication and must never be relabelled as login reuse.

## Cleanup and reporting

- Never commit, upload, publish, attach, or include the state file in a deliverable.
- Close the disposable test session before cleanup.
- Verify the exact resolved temporary file and profile paths, then remove only those task-specific artifacts with a recoverable deletion mechanism.
- Do not print storage contents in logs or final responses. Report only the tested synthetic key names and whether the roundtrip passed.
- If a real secret appears unexpectedly, stop, avoid copying it, delete the unshared temporary artifact, and report the exposure without repeating the value.

SHA-256: bbb583bc1486be7d2d9e0e124b9d8ef1c466bc5f0ca7b340022be8b0f8cddcc1