Password Depot for Android — QA Test Report

Build 20.0.0-beta13 (1943) · Round 13 · Generated 9/15/2026, 3:17:24 PM

1 · Environment

Device / AndroidSamsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
KeyboardSamsung Keyboard 5.9.12, Microsoft SwiftKey, Gboard
Browser(s)Chrome 152, Edge 152, Firefox 155
Build line20.0.0-beta13 (1943)
TesterSheva Ma
Date started2026-Sep-14

2 · Summary

BlockTotal✅ Pass❌ Fail⏭️ Skip🔄 In Progress⬜ Pending
Part 0 — Round 13 Re-Test: Beta7 Bug Fixes 27185 310
Part 0b — Round 13 New Features (Verify) 1034 210
Part 1 — Core Pass: A1–A10 (Every Tester, Every Device) 1063 010
Part 3 — Focus Blocks C1–C11 1181 200
Total583513 730
Items tested / total55 / 58
Pass rate (of decided items)73%
Failures13
Skipped7

3 · Failures (13)

R1 AC-458 App language messages follow app language, even after a system-language change
Section: Part 0 — Round 13 Re-Test: Beta7 Bug Fixes
Tested device: Samsung Galaxy S22
Comments / Jira key: Reopened.
R9 AC-475 Clipboard notification has a "Clear now" action
Section: Part 0 — Round 13 Re-Test: Beta7 Bug Fixes
Tested device: Samsung Galaxy S22
Comments / Jira key: Repopened, issue still happens on samsung devices, but not on pixel device.
R16 AC-487 Category drop-down lists all categories
Section: Part 0 — Round 13 Re-Test: Beta7 Bug Fixes
Tested device: Samsung Galaxy S22
Comments / Jira key: Issue still reproducible.
R18 AC-493 / AC-494 Autofill option appears in Edge and Samsung Internet
Section: Part 0 — Round 13 Re-Test: Beta7 Bug Fixes
Tested device: Samsung Galaxy S22
Comments / Jira key: Reopened
R20 AC-496 No crash when navigating the entry list on tablets
Section: Part 0 — Round 13 Re-Test: Beta7 Bug Fixes
Tested device: Samsung Galaxy S22
Comments / Jira key: Issue still reproducible.
N1 AC-480 Second-password Entries in Autofill
Section: Part 0b — Round 13 New Features (Verify)
Tested device: Samsung Galaxy S22
Comments / Jira key: Autofill with second password entries works fine, but there is a issue found: https://internal.tracker.password-depot.de/browse/AC-508
N4 AC-65 Icon from the Web
Section: Part 0b — Round 13 New Features (Verify)
Tested device: Samsung Galaxy S22
Comments / Jira key: Bug:
https://internal.tracker.password-depot.de/browse/AC-509

Improvement:
https://internal.tracker.password-depot.de/browse/AC-510
N5 AC-450 QR-Code Scanner for TOTP Setup
Section: Part 0b — Round 13 New Features (Verify)
Tested device: Samsung Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-512
https://internal.tracker.password-depot.de/browse/AC-513
N9 AC-497 (client part) Sign-in Error Messages
Section: Part 0b — Round 13 New Features (Verify)
Tested device: Samsung Galaxy S22
Comments / Jira key: — none —
A6 Clipboard
Section: Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)
Tested device: Samsung Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-475
A9 Appearance, Language, Rotation, Tablet
Section: Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)
Tested device: Samsung Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-458
A10 Stability & Error Visibility
Section: Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)
Tested device: Samsung Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-496
C3 WebDAV Sync
Section: Part 3 — Focus Blocks C1–C11
Tested device: Samsung Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-506
https://internal.tracker.password-depot.de/browse/AC-507

3b · Skipped (7)

IDTitleReason
R8Dropbox authorization no longer loops after cancellingBlcked by AC-457.
R13Database list is reachable without a local databaseOlha will verify it.
R19"Unlock with the master password" note disappears after unlockingJonas will verify it.
N2Offline Copy for Single Sign-On AccountsCurrent Enterprise server v19 is not support 25020 port, hence cannot test this feature.
N10Dropbox — SKIP THIS ROUNDSkipped per Round 13 instructions.
C9Enterprise Offline CopyNo ES v20 available for testing.
C11Hand-Over of Previous-App Offline ChangesNo ES v20 available for testing.

4 · Detailed Results

Part 0 — Round 13 Re-Test: Beta7 Bug Fixes

These bugs were reported in previous rounds and claimed fixed. Re-test every one on build 1943.

R1AC-458 ❌ FAIL
App language messages follow app language, even after a system-language change
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
Reopened.
R2AC-459 ✅ PASS
Enterprise Server: free fields of a server entry can be edited; opening an entry no longer changes its type
Result
Status: ✅ PASS
Comments:
— none —
R3AC-464 ✅ PASS
WebDAV: opening a database requires no write permission; server answer never reported as "could not be reached"
Result
Status: ✅ PASS
Comments:
Followed up AC-506,
R4AC-469 ✅ PASS
"Change master password" stays open after a wrong current password and shows error at the field
Result
Status: ✅ PASS
Comments:
— none —
R5AC-470 ✅ PASS
The "URLs (n)" counter matches what the card shows
Result
Status: ✅ PASS
Tested device: test
Comments:
— none —
R6AC-471 / AC-478 ✅ PASS
No "Session expired" message appears after a completed autofill
Result
Status: ✅ PASS
Comments:
— none —
R7AC-472 ✅ PASS
Cancelling a cloud sign-in leaves no error on the unlock screen
Result
Status: ✅ PASS
Comments:
— none —
R8AC-474 ⏭️ SKIP
Dropbox authorization no longer loops after cancelling
Result
Status: ⏭️ SKIP
Comments:
Blcked by AC-457.
R9AC-475 ❌ FAIL
Clipboard notification has a "Clear now" action
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
Repopened, issue still happens on samsung devices, but not on pixel device.
R10AC-476 ✅ PASS
A saved attachment keeps its file extension
Result
Status: ✅ PASS
Comments:
— none —
R11AC-479 ✅ PASS
Passkey provider is not shown as disabled on Android 14 when it is on
Result
Status: ✅ PASS
Comments:
— none —
R12AC-482 ✅ PASS
Last opened database is marked active, including a server database
Result
Status: ✅ PASS
Comments:
— none —
R13AC-483 ⏭️ SKIP
Database list is reachable without a local database
Result
Status: ⏭️ SKIP
Comments:
Olha will verify it.
R14AC-484 ✅ PASS
Passkey creation works in Chrome and Edge
Result
Status: ✅ PASS
Comments:
Jonas will verify it.
R15AC-486 ✅ PASS
Autofill offers itself when a one-time-code field opens the numeric keyboard
Result
Status: ✅ PASS
Comments:
— none —
R16AC-487 ❌ FAIL
Category drop-down lists all categories
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
Issue still reproducible.
R17AC-489 ✅ PASS
Tablet landscape: navigation bar stays in the Enterprise view
Result
Status: ✅ PASS
Comments:
Issue fixed, but a new isuse https://internal.tracker.password-depot.de/browse/AC-505 fixed.
R18AC-493 / AC-494 ❌ FAIL
Autofill option appears in Edge and Samsung Internet
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
Reopened
R19AC-495 ⏭️ SKIP
"Unlock with the master password" note disappears after unlocking
Result
Status: ⏭️ SKIP
Comments:
Jonas will verify it.
R20AC-496 ❌ FAIL
No crash when navigating the entry list on tablets
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
Issue still reproducible.
R21AC-498 ✅ PASS
Saving an offline copy from Server 19 names the server version and says copies need Server 20
Result
Status: ✅ PASS
Tested device: Samsung Galaxy S22
Comments:
— none —
R22AC-501 ✅ PASS
TOTP settings (algorithm, digits, period) match the Windows dialog
Result
Status: ✅ PASS
Comments:
— none —
R23AC-502 ✅ PASS
A backup copy of a key-file database asks for the key file
Result
Status: ✅ PASS
Comments:
— none —
R24AC-503 🔄 IN PROGRESS
Last row and "Create" button of full-screen forms not hidden under navigation bar (Android 15+)
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
R25AC-473 ✅ PASS
German wording matches the Windows client
Result
Status: ✅ PASS
Comments:
— none —
R26AC-488 ✅ PASS
Support data: smaller log font, actions on top
Result
Status: ✅ PASS
Comments:
— none —
R27AC-500 ✅ PASS
"Confirm and search" is disabled without a screen lock and links to system settings
Result
Status: ✅ PASS
Comments:
— none —

Part 0b — Round 13 New Features (Verify)

New in this build. Verify each feature works as described.

N1AC-480 ❌ FAIL
Second-password Entries in Autofill
What to test: Entries protected with a second password must be offered in autofill. The fill window must ask for the second password before filling.
Steps
  1. Create a password entry with a second password ("four eyes") set.
  2. Open a browser login form matching that entry's URL.
  3. Trigger autofill.
Expected
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
Autofill with second password entries works fine, but there is a issue found: https://internal.tracker.password-depot.de/browse/AC-508
N2AC-84 ⏭️ SKIP
Offline Copy for Single Sign-On Accounts
What to test: An account that signed in via SSO can save and open an offline copy. The copy is device-bound and cannot be moved.
Steps
  1. Sign in to Enterprise Server using Single Sign-On (OpenID Connect / Entra ID).
  2. Tap "Save offline copy…" from the database list.
  3. Sign out; open the offline copy.
  4. Attempt to copy the offline copy to another device.
Expected
Result
Status: ⏭️ SKIP
Comments:
Current Enterprise server v19 is not support 25020 port, hence cannot test this feature.
N3AC-481 ✅ PASS
Autofill After Server Session Ended
What to test: The fill window notifies the user that the last database was on the server and offers to sign in. After sign-in, filling continues. Requires a device screen lock.
Steps
  1. Open a server database.
  2. Let the server session expire / sign out.
  3. Trigger autofill in a browser.
Expected
Result
Status: ✅ PASS
Comments:
— none —
N4AC-65 ❌ FAIL
Icon from the Web
What to test: The icon picker in the editor offers "Load from the web". Only the host name leaves the device. Icon is shown as preview before being applied.
Steps
  1. Open any entry in the editor.
  2. Tap the icon → "Load from the web".
  3. Observe the preview; confirm.
Expected
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
Bug:
https://internal.tracker.password-depot.de/browse/AC-509

Improvement:
https://internal.tracker.password-depot.de/browse/AC-510
N5AC-450 ❌ FAIL
QR-Code Scanner for TOTP Setup
What to test: Editor offers "Scan QR code" for entries without a one-time code. Works with camera and photos. Camera permission requested on first use. Invalid QR codes are rejected with a message.
Steps
  1. Open an entry without TOTP in the editor.
  2. Tap "Scan QR code" → first use should prompt for camera permission.
  3. Scan a real authenticator QR code.
  4. Attempt to scan a non-authenticator QR code.
Expected
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
https://internal.tracker.password-depot.de/browse/AC-512
https://internal.tracker.password-depot.de/browse/AC-513
N6AC-504 / AC-468 ✅ PASS
Server Entry Editor: Local-style Fields
What to test: Server entry editor shows category, importance, expiry date and tags in Windows order; includes password generator and strength meter. Detail view shows expiry as a calendar day.
Known issue / note: ⚠️ Known server issue (ES-988): Server delivers importance inverted (Windows "High" = "Low" and vice versa). This is a server bug — do NOT file as an app bug.
Steps
  1. Open a server entry in the editor.
  2. Check for: category, importance, expiry date, tags, password generator, strength meter.
  3. Save and check the detail view for the expiry date.
Expected
Result
Status: ✅ PASS
Comments:
— none —
N7AC-467 (part 1) 🔄 IN PROGRESS
One Database List
What to test: Database list shows every server database opened, with its account. Tap to sign in with account pre-filled. Can open properties or remove from list. Removing does not change anything on the server.
Steps
  1. Connect to at least two different server databases from different accounts.
  2. Open the database list.
  3. Tap a row: verify account is pre-filled for sign-in.
  4. Remove a row; verify the database still exists on the server.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
N8AC-499 ✅ PASS
Two-Factor Setup on Server
What to test: On first 2FA sign-in, the QR code is accompanied by the secret key as text with a copy button (for authenticator apps on the same device).
Steps
  1. Sign in to a server account that has 2FA enabled for the first time.
  2. Observe the 2FA setup screen.
Expected
Result
Status: ✅ PASS
Comments:
https://internal.tracker.password-depot.de/browse/AC-513
N9AC-497 (client part) ❌ FAIL
Sign-in Error Messages
What to test: App distinguishes "server could not send authentication e-mail" from "no e-mail address stored for this account".
Known issue / note: ⚠️ Until server ticket ES-987 is resolved, the server still reports "user name or password is wrong" for both cases. The app distinction is prepared but may not be visible yet.
Steps
  1. Attempt sign-in with an account with no e-mail stored.
  2. Attempt sign-in triggering a mail delivery failure (if the server supports ES-987).
Expected
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
— none —
N10AC-457 ⏭️ SKIP
Dropbox — SKIP THIS ROUND
What to test: Dropbox sign-in still fails with "Cloud sign-in failed" — the redirect address has not yet been registered in the Dropbox App Console.
Known issue / note: ⏭️ Skipped per Round 13 instructions. Do NOT file this as a bug.
Result
Status: ⏭️ SKIP
Comments:
Skipped per Round 13 instructions.

Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)

Estimated time: 45–60 minutes. Run on every device you test.

A1 ✅ PASS
First Launch & Database Creation
Steps
  1. Fresh install (or update): open the app.
  2. Create a database with a name and a test master password.
  3. Confirm the empty entry list is shown.
  4. Relaunch the app.
  5. Enter the master password; confirm unlock.
  6. Enter a wrong master password.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A2 🔄 IN PROGRESS
Entries of Several Types
Steps
  1. Create the following entries: password entry (with URL of a test account), credit card (PIN/CVV), identity entry, information entry, entry with a protected custom field.
  2. While typing secret fields (password, PIN, CVV, protected values), verify keyboard behavior.
  3. Open detail view for each entry.
  4. Edit each entry and re-save.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
IMPROVEMENT: https://internal.tracker.password-depot.de/browse/AC-514
ISSUE: https://internal.tracker.password-depot.de/browse/AC-515
A3 ✅ PASS
Folders, Search, Trash
Steps
  1. Create two folders.
  2. Move entries between them.
  3. Search by title, username, and URL.
  4. Delete an entry (move to trash).
  5. Restore it from the recycle bin.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A4 ✅ PASS
Locking
Steps
  1. Background the app and return quickly (within the auto-lock time).
  2. Stay away past the auto-lock time (Settings → Security → Auto-lock).
  3. Force-close the app from Recents.
  4. Relaunch.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A5 ✅ PASS
Biometric Unlock + Invalidation
Steps
  1. Enable Settings → Security → Biometric unlock.
  2. Lock the database.
  3. Unlock using fingerprint/face.
  4. Go to Android system settings and enroll an additional fingerprint.
  5. Return to the app.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A6 ❌ FAIL
Clipboard
Steps
  1. Copy a password from the detail view.
  2. Check if a countdown notification appears (Android 13+: grant notification permission if asked).
  3. Paste the password in another app — confirm it works.
  4. Wait 30 seconds; attempt to paste again.
  5. Try the "Clear now" button in the notification.
  6. Check the keyboard's own clipboard history (Samsung/Gboard/SwiftKey).
Expected
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
https://internal.tracker.password-depot.de/browse/AC-475
A7 ✅ PASS
Autofill in Your Daily Browser
Note: ⚠️ Chrome 131+ extra step required: Chrome → Settings → Autofill services → "Autofill using another service" → restart Chrome.
Steps
  1. Enable Settings → Autofill service (follow system dialogs).
  2. Open Settings → Autofill test; confirm the suggestion appears on the built-in test form.
  3. Navigate to a test account login page in your browser.
  4. Verify autofill suggestion appears (inline chip or system sheet).
  5. Fill with Password Depot; confirm fields are filled correctly.
  6. Log in with a new credential typed manually; confirm save/update prompt appears.
  7. Negative check: navigate to a different or look-alike domain; confirm the entry is NOT offered under "Matching this site".
Expected
Result
Status: ✅ PASS
Comments:
— none —
A8 ✅ PASS
Autofill in One App
Steps
  1. Open any app with a login screen (use a test account).
  2. Trigger autofill.
  3. Test an app using Android Credential Manager (e.g. Facebook) if available.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A9 ❌ FAIL
Appearance, Language, Rotation, Tablet
Steps
  1. Switch appearance: dark → light → system mode.
  2. Switch app language DE ↔ EN (Settings → App language on Android 13+).
  3. Rotate the device while unlocked; confirm session and selection survive.
  4. (Tablet/foldable only) Verify the two-pane list+detail layout.
  5. Note any clipped, untranslated, or oddly-worded text.
Expected
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
https://internal.tracker.password-depot.de/browse/AC-458
A10 ❌ FAIL
Stability & Error Visibility
What to test: What to watch for throughout testing: any crash or ANR (app not responding); any freeze that requires a force-close; any error that is swallowed silently (action appears to work but data is wrong).
Steps
  1. If any of the above occur, open Support data immediately (lock → "Support data…" on unlock screen).
  2. Copy the version line and any listed events.
  3. File a Jira Bug with Sev-0 and attach the support data.
Expected
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
https://internal.tracker.password-depot.de/browse/AC-496

Part 3 — Focus Blocks C1–C11

Complete the blocks assigned to you, or any you have the setup for.

C1 ✅ PASS
TOTP
Setup needed: A test account with 2FA / TOTP setup, and a reference authenticator app.
Steps
  1. Add a TOTP secret to a test entry using the entry editor.
  2. In Round 13: use "Scan QR code" (camera or photo) to add the TOTP secret — test the new QR scanner.
  3. Compare the 6-digit code with a reference authenticator for at least 3 consecutive periods.
  4. With autofill: open the 2FA field on a login page; confirm the code is offered only into the one-time-code field.
  5. Confirm the code is never offered into user/password fields.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C2 ✅ PASS
Passkeys (Android 14+)
Setup needed: Android 14+, device screen lock enabled. Test site: https://webauthn.io
Steps
  1. Settings → Passkey provider → select Password Depot. Verify the row shows "Enabled".
  2. On webauthn.io: register a new passkey (should land in the Password Depot database).
  3. Sign in with the passkey using the same database.
  4. Move the passkey entry to the trash.
  5. Attempt sign-in again → expect "No matching passkey in the database".
  6. Restore the passkey entry.
  7. Attempt sign-in again → confirm it works.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C3 ❌ FAIL
WebDAV Sync
Setup needed: A real Nextcloud and/or Apache WebDAV server over HTTPS.
Steps
  1. Link the WebDAV server (Settings → Storage location & sync).
  2. Perform the initial database upload.
  3. Edit an entry on Android; sync; verify on Windows.
  4. Edit the same entry on both Android and Windows simultaneously.
  5. Sync from Android.
Expected
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
https://internal.tracker.password-depot.de/browse/AC-506
https://internal.tracker.password-depot.de/browse/AC-507
C4 ✅ PASS
Windows Interop
Setup needed: Windows Password Depot 19 and the same database accessible on both (file copy or WebDAV).
Steps
  1. Open the same .pswe file alternately in Windows PD 19 and Android.
  2. Verify that the following survive both directions (Android→Windows, Windows→Android): entries with umlauts/emoji in titles, folders and sub-folders, attachments, TAN lists (kept in file even though Android does not display them), entry history, custom icons, second-password ("four eyes") entry.
  3. Specifically: set an expiry date on Android; open in Windows; confirm the date is preserved.
  4. Edit the same entry on both sides; sync; confirm a conflict copy appears rather than a silent overwrite.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C5 ✅ PASS
Attachments
Steps
  1. Attach a photo (a few MB) to an entry; reopen and export it; verify the file is intact.
  2. Attach a PDF (a few MB) to an entry; reopen and export it; verify the file is intact.
  3. Attempt to attach a file over 25 MB.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C6 ✅ PASS
Multi-Database & Master Password Change
Steps
  1. Create a second database; switch between both databases.
  2. "Remove from app" on one database; confirm the database file still exists and can be re-added.
  3. Change the master password of a test database.
  4. Attempt to unlock with the old password.
  5. Check biometric unlock status.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C7 ✅ PASS
Backup & Restore
Steps
  1. Navigate to Databases & sync → Backup copies; create a backup of a test database.
  2. Make a few changes to the database.
  3. Restore an earlier backup copy.
  4. Enter a wrong password during restore; check for throttle (3 s / 10 s delay) and message.
  5. Enter the correct password; confirm restore.
  6. Verify the restored state is complete; confirm the previous state was saved as a new backup copy first; confirm the chosen copy is still listed.
  7. (If database is linked to a storage source) Confirm a notice says the next sync will merge instead of replace.
  8. Attempt to restore a deliberately corrupted backup file.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C8 ✅ PASS
Enterprise Thin Client
Setup needed: Office test server (Enterprise Server 20).
Steps
  1. Open the app → "Enterprise server…" on the start screen.
  2. Enter the server address and port; log in.
  3. On first connect: verify the TLS fingerprint confirmation dialog appears. Compare the SHA-256 with the server certificate (Windows: Home → PD Enterprise Server → "View server certificate").
  4. Confirm server and port are remembered after the first successful login.
  5. Browse and search entries on the server.
  6. Edit an entry and save.
  7. Test sign-in with Windows domain credentials (DOMAIN\user or user@company.com) if AD is available.
Expected
Result
Status: ✅ PASS
Comments:
https://internal.tracker.password-depot.de/browse/AC-511
C9 ⏭️ SKIP
Enterprise Offline Copy
Setup needed: Enterprise Server 20, TCP port 25020, a database with the offline right granted.
Steps
  1. Sign in to the server; tap "Save offline copy…" on the database list.
  2. Enter the server password (2FA accounts get a code field in step 2).
  3. Tap "Load databases" — confirm the TLS fingerprint once.
  4. Pick a database; confirm the copy is saved.
  5. Sign out; tap "Open offline copy" on the login screen; open with the server password.
  6. Verify the status line reads "Enterprise Server · offline copy".
  7. Create/edit an entry offline; note the waiting-changes counter in the status line.
  8. Settings → Sync… → "Send changes to the server": certificate question appears inside this screen; enter fingerprint; confirm all changes sent; "Load fresh copy" offered.
  9. Check: entry the server marks as non-editable → no edit action shown.
  10. Check: without export/save-as rights → Export and "Save as" are absent.
  11. Check: "Usable until" date matches the server's offline period.
  12. Check: offline copy cannot be linked to cloud/WebDAV storage.
  13. Enter a wrong server password for an existing copy; confirm the error names the password (not "changes waiting").
Expected
Result
Status: ⏭️ SKIP
Comments:
No ES v20 available for testing.
C10 ✅ PASS
Enterprise Single Sign-On (OpenID Connect / Entra ID)
Setup needed: Enterprise Server 20 with a configured OpenID Connect or Entra ID sign-in provider; the provider registration must contain the redirect oidc.acebit://password-depot.de/.
Steps
  1. Choose "Single sign-on (OpenID Connect / Entra ID)" in the Enterprise login; tap "Connect".
  2. Complete sign-in in the browser; confirm the app returns to the database list.
  3. Sign out; use "Sign in with a different account"; confirm the provider prompts for account selection.
  4. Start a sign-in and cancel it in the browser; confirm the app shows "The sign-in in the browser was cancelled".
  5. Sign in with an account the server does not know; expect "The Enterprise Server did not accept the sign-in…".
  6. Rotate the device while the browser is open; confirm the sign-in continues.
  7. Press Home during sign-in and return via the browser.
  8. (If configured) Test the second factor after sign-in.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C11 ⏭️ SKIP
Hand-Over of Previous-App Offline Changes
Setup needed: Enterprise Server 20, TCP port 25020. Either a previous-app installation with unsent offline changes, or the prepared file from the dev team.
Steps
  1. Start with the previous Password Depot for Android app installed and an Enterprise database with unsent offline changes.
  2. Update to this build; open "Import from previous app"; take the database over.
  3. Verify the report names the number of unsent changes and says they can be sent from the database.
  4. "Unlock now": confirm the note at the top shows the same number.
  5. Tap "Send to the server…": port 25020 and database name pre-filled; enter server, account, password.
  6. On first contact: certificate fingerprint question appears inside the dialog — enter it.
  7. Confirm the note disappears and the changes are on the server (verify in the Windows client).
  8. Test with a rejected change (e.g. no delete permission): note stays and names the reason; a later send tries only remaining open changes.
  9. Confirm the database never silently loses the note.
Expected
Result
Status: ⏭️ SKIP
Comments:
No ES v20 available for testing.

5 · Device Matrix Contribution

DimensionVariantCoveredNotes
Keyboard Gboard ✅
Keyboard Samsung Keyboard ✅
Keyboard SwiftKey ✅
Browser Chrome ✅
Browser Edge ❌ https://internal.tracker.password-depot.de/browse/AC-493
Browser Firefox ✅
Browser Samsung Internet ❌ https://internal.tracker.password-depot.de/browse/AC-494
Autofill style Android 11+ inline chips (note which you saw) —
Autofill style Android ≤13 dropdown ✅
Clipboard Samsung clipboard behavior ❌ https://internal.tracker.password-depot.de/browse/AC-475
Clipboard Pixel clipboard behavior ✅
Clipboard Xiaomi clipboard behavior ❌ https://internal.tracker.password-depot.de/browse/AC-524
Biometrics Fingerprint ✅
Biometrics Face unlock ✅
Biometrics Both enrolled n/a No real device for testing.
OEM quirks Xiaomi/HyperOS battery saver — auto-lock reliable? n/a No real device for testing.
OEM quirks Samsung battery saver — session killed mid-edit? ✅
Form factor Phone ✅
Form factor Tablet (≥ 600 dp) ✅
Form factor Foldable n/a No device

6 · Reporting Reference

Jira ProjectAndroid Client (AC)
Issue Type (bugs)Bug
Issue Type (coverage)Task
Affects Version20.0.0
Build line20.0.0-beta13 (1943)
Severity 0crash · data loss · lock-out
Severity 1feature wrong or unusable
Severity 2wrong, has a workaround
Severity 3visual / text
Deadlinewithin 10 working days
Bug summary format<area>: <short title>
Coverage summary formatBeta coverage: <device>

Support data: lock the app → tap "Support data…" on the unlock screen. Strictly local, secret-free. Copy version line + events into the issue.