This XHTML document GETs another resource using cross-site XHR and sends that request with credentials. If you get a response back, the content of that response should reflect Cookies being sent, since the XMLHttpRequest invocation on this page sets the withCredentials flag.