diff --git a/core/modules/system/src/Tests/Session/SessionAuthenticationTest.php b/core/modules/system/src/Tests/Session/SessionAuthenticationTest.php
index 121bc34..15335b5 100644
--- a/core/modules/system/src/Tests/Session/SessionAuthenticationTest.php
+++ b/core/modules/system/src/Tests/Session/SessionAuthenticationTest.php
@@ -78,4 +78,28 @@ public function testSessionFromBasicAuthenticationDoesNotLeak() {
     $this->assertResponse(401, 'A subsequent request to the same route without basic authentication is not authorized.');
   }
 
+  /**
+   * Checks that no session cookie is saved when using basic authentication.
+   */
+  public function testOnlyCookieGetsACookie() {
+    // A route that is authorized through basic_auth only, not cookie.
+    $no_cookie_url = Url::fromRoute('session_test.get_session_basic_auth');
+
+    // A route that is authorized with standard cookie authentication.
+    $cookie_url = '<front>';
+
+    // If we authenticate with a third party authentication system then no
+    // session cookie should be set, the third party system is responsible for
+    // sustaining the session.
+    $this->basicAuthGet($no_cookie_url, $this->user->getUsername(), $this->user->pass_raw);
+    $this->assertResponse(200, 'The user is successfully authenticated using basic authentication.');
+    $this->assertNull($this->cookies, 'A route protected with basic authentication does not yield a cookie.');
+
+    // On the other hand, authenticating using Cookie yields a cookie.
+    $edit = ['name' => $this->user->getUsername(), 'pass' => $this->user->pass_raw];
+    $this->drupalPostForm($cookie_url, $edit, t('Log in'));
+    $this->assertResponse(200, 'The user is successfully authenticated using cookie authentication.');
+    $this->assertNotNull($this->cookies, 'A route protected with cookie authentication yields a cookie.');
+  }
+
 }
