AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

`@Next/Playwright Instant()` Clears Testing Cookies For Other Origins

The @next/playwright instant() helper removes the next-instant-navigation-testing cookie for all origins in a shared Playwright BrowserContext, instead of only the application URL it is controlling. This breaks multi-origin test scenarios where app B's testing cookie is deleted when instant() is called for app A.

mediumConfidence 78%Next.jsAffected V16.3.1-Canary.8

Origin Analysis

The instant() cleanup logic uses an unscoped cookie removal, likely `context.clearCookies({ name: 'next-instant-navigation-testing' })` or `context.clearCookies()` without a domain or URL filter. Playwright's clearCookies with only a name deletes matching cookies across all origins in the context, causing cross-app interference.
1. Clone the reproduction repo and switch to branch `repro/next-playwright-origin-cookie/next-playwright-origin-cookie-repro`. 2. Run `npm install` and `npx playwright install chromium`. 3. Run `npm test`. 4. Observe assertion failure: the `next-instant-navigation-testing` cookie for `app-b.example` is removed after calling `instant()` for `app-a.example`.

Fixing Code Block

import type { BrowserContext } from 'playwright'; async function clearInstantNavigationCookies( context: BrowserContext, baseURL: string ) { const targetUrl = new URL(baseURL); const cookies = await context.cookies(targetUrl.toString()); const testCookies = cookies.filter( (cookie) => cookie.name === 'next-instant-navigation-testing' ); await Promise.all( testCookies.map((cookie) => context.clearCookies({ name: cookie.name, domain: cookie.domain, path: cookie.path, }) ) ); }
Instead of clearing by name only, first retrieve all cookies that apply to the target base URL using `context.cookies(targetUrl)`. Then filter only the specific testing cookie and clear each matched cookie individually by its exact domain and path. This scopes cleanup to the application being controlled and preserves same-named cookies for other origins.

Edge Case Audit

Playwright's cookie domain matching has edge cases: if a cookie is set with a leading dot (e.g., `.example.com`), clearing by hostname alone may not remove it; using `context.cookies(url)` and exact domain/path avoids that. For rollback, revert to the previous unscoped clear behavior. Avoid running multiple `instant()` calls concurrently in the same BrowserContext, as cookie mutation may race. If tests share a context across origins, isolate them per-origin to reduce cross-app coupling.

Ecosystem Topology