Password Depot for Android — QA Test Report
Build 20.0.0-beta13 (1943) · Round 13 · Generated 9/15/2026, 3:17:24 PM
1 · Environment
| Device / Android | Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11 |
|---|
| Keyboard | Samsung Keyboard 5.9.12, Microsoft SwiftKey, Gboard |
|---|
| Browser(s) | Chrome 152, Edge 152, Firefox 155 |
|---|
| Build line | 20.0.0-beta13 (1943) |
|---|
| Tester | Sheva Ma |
|---|
| Date started | 2026-Sep-14 |
|---|
2 · Summary
| Block | Total | ✅ Pass | ❌ Fail | ⏭️ Skip | 🔄 In Progress | ⬜ Pending |
| Part 0 — Round 13 Re-Test: Beta7 Bug Fixes |
27 | 18 | 5 |
3 | 1 | 0 |
| Part 0b — Round 13 New Features (Verify) |
10 | 3 | 4 |
2 | 1 | 0 |
| Part 1 — Core Pass: A1–A10 (Every Tester, Every Device) |
10 | 6 | 3 |
0 | 1 | 0 |
| Part 3 — Focus Blocks C1–C11 |
11 | 8 | 1 |
2 | 0 | 0 |
| Total | 58 | 35 | 13 |
7 | 3 | 0 |
| Items tested / total | 55 / 58 |
| Pass rate (of decided items) | 73% |
| Failures | 13 |
| Skipped | 7 |
3 · Failures (13)
R1
AC-458
App language messages follow app language, even after a system-language change
Section: Part 0 — Round 13 Re-Test: Beta7 Bug Fixes
Tested device: Samsung Galaxy S22
Comments / Jira key: Reopened.
R9
AC-475
Clipboard notification has a "Clear now" action
Section: Part 0 — Round 13 Re-Test: Beta7 Bug Fixes
Tested device: Samsung Galaxy S22
Comments / Jira key: Repopened, issue still happens on samsung devices, but not on pixel device.
R16
AC-487
Category drop-down lists all categories
Section: Part 0 — Round 13 Re-Test: Beta7 Bug Fixes
Tested device: Samsung Galaxy S22
Comments / Jira key: Issue still reproducible.
R18
AC-493 / AC-494
Autofill option appears in Edge and Samsung Internet
Section: Part 0 — Round 13 Re-Test: Beta7 Bug Fixes
Tested device: Samsung Galaxy S22
Comments / Jira key: Reopened
R20
AC-496
No crash when navigating the entry list on tablets
Section: Part 0 — Round 13 Re-Test: Beta7 Bug Fixes
Tested device: Samsung Galaxy S22
Comments / Jira key: Issue still reproducible.
N1
AC-480
Second-password Entries in Autofill
Section: Part 0b — Round 13 New Features (Verify)
Tested device: Samsung Galaxy S22
Comments / Jira key: Autofill with second password entries works fine, but there is a issue found: https://internal.tracker.password-depot.de/browse/AC-508
N4
AC-65
Icon from the Web
Section: Part 0b — Round 13 New Features (Verify)
Tested device: Samsung Galaxy S22
Comments / Jira key: Bug:
https://internal.tracker.password-depot.de/browse/AC-509
Improvement:
https://internal.tracker.password-depot.de/browse/AC-510
N5
AC-450
QR-Code Scanner for TOTP Setup
Section: Part 0b — Round 13 New Features (Verify)
Tested device: Samsung Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-512
https://internal.tracker.password-depot.de/browse/AC-513
N9
AC-497 (client part)
Sign-in Error Messages
Section: Part 0b — Round 13 New Features (Verify)
Tested device: Samsung Galaxy S22
Comments / Jira key: — none —
A6
Clipboard
Section: Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)
Tested device: Samsung Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-475
A9
Appearance, Language, Rotation, Tablet
Section: Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)
Tested device: Samsung Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-458
A10
Stability & Error Visibility
Section: Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)
Tested device: Samsung Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-496
C3
WebDAV Sync
Section: Part 3 — Focus Blocks C1–C11
Tested device: Samsung Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-506
https://internal.tracker.password-depot.de/browse/AC-507
3b · Skipped (7)
| ID | Title | Reason |
|---|
| R8 | Dropbox authorization no longer loops after cancelling | Blcked by AC-457. |
| R13 | Database list is reachable without a local database | Olha will verify it. |
| R19 | "Unlock with the master password" note disappears after unlocking | Jonas will verify it. |
| N2 | Offline Copy for Single Sign-On Accounts | Current Enterprise server v19 is not support 25020 port, hence cannot test this feature. |
| N10 | Dropbox — SKIP THIS ROUND | Skipped per Round 13 instructions. |
| C9 | Enterprise Offline Copy | No ES v20 available for testing. |
| C11 | Hand-Over of Previous-App Offline Changes | No ES v20 available for testing. |
4 · Detailed Results
Part 0 — Round 13 Re-Test: Beta7 Bug Fixes
These bugs were reported in previous rounds and claimed fixed. Re-test every one on build 1943.
R1AC-458 ❌ FAIL
App language messages follow app language, even after a system-language change
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
R2AC-459 ✅ PASS
Enterprise Server: free fields of a server entry can be edited; opening an entry no longer changes its type
Result
Status: ✅ PASS
Comments:
R3AC-464 ✅ PASS
WebDAV: opening a database requires no write permission; server answer never reported as "could not be reached"
Result
Status: ✅ PASS
Comments:
R4AC-469 ✅ PASS
"Change master password" stays open after a wrong current password and shows error at the field
Result
Status: ✅ PASS
Comments:
R5AC-470 ✅ PASS
The "URLs (n)" counter matches what the card shows
Result
Status: ✅ PASS
Tested device: test
Comments:
R6AC-471 / AC-478 ✅ PASS
No "Session expired" message appears after a completed autofill
Result
Status: ✅ PASS
Comments:
R7AC-472 ✅ PASS
Cancelling a cloud sign-in leaves no error on the unlock screen
Result
Status: ✅ PASS
Comments:
R8AC-474 ⏭️ SKIP
Dropbox authorization no longer loops after cancelling
Result
Status: ⏭️ SKIP
Comments:
R9AC-475 ❌ FAIL
Clipboard notification has a "Clear now" action
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
R10AC-476 ✅ PASS
A saved attachment keeps its file extension
Result
Status: ✅ PASS
Comments:
R11AC-479 ✅ PASS
Passkey provider is not shown as disabled on Android 14 when it is on
Result
Status: ✅ PASS
Comments:
R12AC-482 ✅ PASS
Last opened database is marked active, including a server database
Result
Status: ✅ PASS
Comments:
R13AC-483 ⏭️ SKIP
Database list is reachable without a local database
Result
Status: ⏭️ SKIP
Comments:
R14AC-484 ✅ PASS
Passkey creation works in Chrome and Edge
Result
Status: ✅ PASS
Comments:
R15AC-486 ✅ PASS
Autofill offers itself when a one-time-code field opens the numeric keyboard
Result
Status: ✅ PASS
Comments:
R16AC-487 ❌ FAIL
Category drop-down lists all categories
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
R17AC-489 ✅ PASS
Tablet landscape: navigation bar stays in the Enterprise view
Result
Status: ✅ PASS
Comments:
R18AC-493 / AC-494 ❌ FAIL
Autofill option appears in Edge and Samsung Internet
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
R19AC-495 ⏭️ SKIP
"Unlock with the master password" note disappears after unlocking
Result
Status: ⏭️ SKIP
Comments:
R20AC-496 ❌ FAIL
No crash when navigating the entry list on tablets
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
R21AC-498 ✅ PASS
Saving an offline copy from Server 19 names the server version and says copies need Server 20
Result
Status: ✅ PASS
Tested device: Samsung Galaxy S22
Comments:
R22AC-501 ✅ PASS
TOTP settings (algorithm, digits, period) match the Windows dialog
Result
Status: ✅ PASS
Comments:
R23AC-502 ✅ PASS
A backup copy of a key-file database asks for the key file
Result
Status: ✅ PASS
Comments:
R24AC-503 🔄 IN PROGRESS
Last row and "Create" button of full-screen forms not hidden under navigation bar (Android 15+)
Result
Status: 🔄 IN PROGRESS
Comments:
R25AC-473 ✅ PASS
German wording matches the Windows client
Result
Status: ✅ PASS
Comments:
R26AC-488 ✅ PASS
Support data: smaller log font, actions on top
Result
Status: ✅ PASS
Comments:
R27AC-500 ✅ PASS
"Confirm and search" is disabled without a screen lock and links to system settings
Result
Status: ✅ PASS
Comments:
Part 0b — Round 13 New Features (Verify)
New in this build. Verify each feature works as described.
N1AC-480 ❌ FAIL
Second-password Entries in Autofill
What to test: Entries protected with a second password must be offered in autofill. The fill window must ask for the second password before filling.
Steps
- Create a password entry with a second password ("four eyes") set.
- Open a browser login form matching that entry's URL.
- Trigger autofill.
Expected
- The entry is offered.
- After selecting it, a prompt asks for the second password.
- After entering it, the fields are filled.
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
N2AC-84 ⏭️ SKIP
Offline Copy for Single Sign-On Accounts
What to test: An account that signed in via SSO can save and open an offline copy. The copy is device-bound and cannot be moved.
Steps
- Sign in to Enterprise Server using Single Sign-On (OpenID Connect / Entra ID).
- Tap "Save offline copy…" from the database list.
- Sign out; open the offline copy.
- Attempt to copy the offline copy to another device.
Expected
- Offline copy saves and opens successfully.
- Copy cannot be used on another device.
Result
Status: ⏭️ SKIP
Comments:
N3AC-481 ✅ PASS
Autofill After Server Session Ended
What to test: The fill window notifies the user that the last database was on the server and offers to sign in. After sign-in, filling continues. Requires a device screen lock.
Steps
- Open a server database.
- Let the server session expire / sign out.
- Trigger autofill in a browser.
Expected
- Fill window shows message about the server database.
- Offers sign-in; after sign-in, fill completes.
Result
Status: ✅ PASS
Comments:
N4AC-65 ❌ FAIL
Icon from the Web
What to test: The icon picker in the editor offers "Load from the web". Only the host name leaves the device. Icon is shown as preview before being applied.
Steps
- Open any entry in the editor.
- Tap the icon → "Load from the web".
- Observe the preview; confirm.
Expected
- Site icon fetched and shown as preview.
- Applied after confirmation; no full URL sent externally.
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
N5AC-450 ❌ FAIL
QR-Code Scanner for TOTP Setup
What to test: Editor offers "Scan QR code" for entries without a one-time code. Works with camera and photos. Camera permission requested on first use. Invalid QR codes are rejected with a message.
Steps
- Open an entry without TOTP in the editor.
- Tap "Scan QR code" → first use should prompt for camera permission.
- Scan a real authenticator QR code.
- Attempt to scan a non-authenticator QR code.
Expected
- Permission dialog shown on first use.
- Valid TOTP QR code: TOTP secret applied to the entry.
- Non-authenticator QR code: named as such, scanner stays open.
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
N6AC-504 / AC-468 ✅ PASS
Server Entry Editor: Local-style Fields
What to test: Server entry editor shows category, importance, expiry date and tags in Windows order; includes password generator and strength meter. Detail view shows expiry as a calendar day.
Known issue / note: ⚠️ Known server issue (ES-988): Server delivers importance inverted (Windows "High" = "Low" and vice versa). This is a server bug — do NOT file as an app bug.
Steps
- Open a server entry in the editor.
- Check for: category, importance, expiry date, tags, password generator, strength meter.
- Save and check the detail view for the expiry date.
Expected
- All fields present in correct order.
- Expiry shown as calendar day.
Result
Status: ✅ PASS
Comments:
N7AC-467 (part 1) 🔄 IN PROGRESS
One Database List
What to test: Database list shows every server database opened, with its account. Tap to sign in with account pre-filled. Can open properties or remove from list. Removing does not change anything on the server.
Steps
- Connect to at least two different server databases from different accounts.
- Open the database list.
- Tap a row: verify account is pre-filled for sign-in.
- Remove a row; verify the database still exists on the server.
Expected
- All previously opened server databases listed.
- Row actions (sign in, properties, remove) work correctly.
Result
Status: 🔄 IN PROGRESS
Comments:
N8AC-499 ✅ PASS
Two-Factor Setup on Server
What to test: On first 2FA sign-in, the QR code is accompanied by the secret key as text with a copy button (for authenticator apps on the same device).
Steps
- Sign in to a server account that has 2FA enabled for the first time.
- Observe the 2FA setup screen.
Expected
- QR code shown alongside the plaintext secret key and a copy button.
Result
Status: ✅ PASS
Comments:
N9AC-497 (client part) ❌ FAIL
Sign-in Error Messages
What to test: App distinguishes "server could not send authentication e-mail" from "no e-mail address stored for this account".
Known issue / note: ⚠️ Until server ticket ES-987 is resolved, the server still reports "user name or password is wrong" for both cases. The app distinction is prepared but may not be visible yet.
Steps
- Attempt sign-in with an account with no e-mail stored.
- Attempt sign-in triggering a mail delivery failure (if the server supports ES-987).
Expected
- Distinct error messages for each case (once server sends the new codes).
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
N10AC-457 ⏭️ SKIP
Dropbox — SKIP THIS ROUND
What to test: Dropbox sign-in still fails with "Cloud sign-in failed" — the redirect address has not yet been registered in the Dropbox App Console.
Known issue / note: ⏭️ Skipped per Round 13 instructions. Do NOT file this as a bug.
Result
Status: ⏭️ SKIP
Comments:
Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)
Estimated time: 45–60 minutes. Run on every device you test.
A1 ✅ PASS
First Launch & Database Creation
Steps
- Fresh install (or update): open the app.
- Create a database with a name and a test master password.
- Confirm the empty entry list is shown.
- Relaunch the app.
- Enter the master password; confirm unlock.
- Enter a wrong master password.
Expected
- Empty list shown after creation.
- After relaunch, app is locked.
- Correct password unlocks; wrong password gives a clear error message.
Result
Status: ✅ PASS
Comments:
A2 🔄 IN PROGRESS
Entries of Several Types
Steps
- Create the following entries: password entry (with URL of a test account), credit card (PIN/CVV), identity entry, information entry, entry with a protected custom field.
- While typing secret fields (password, PIN, CVV, protected values), verify keyboard behavior.
- Open detail view for each entry.
- Edit each entry and re-save.
Expected
- Secret fields use a password keyboard: no word suggestions, no swipe input; keyboard must not "learn" the value.
- Detail view shows values readable (matching Windows).
- Nothing lost after edit and save.
Result
Status: 🔄 IN PROGRESS
Comments:
A3 ✅ PASS
Folders, Search, Trash
Steps
- Create two folders.
- Move entries between them.
- Search by title, username, and URL.
- Delete an entry (move to trash).
- Restore it from the recycle bin.
Expected
- All operations complete without errors.
- Restored entry appears back in its original location.
Result
Status: ✅ PASS
Comments:
A4 ✅ PASS
Locking
Steps
- Background the app and return quickly (within the auto-lock time).
- Stay away past the auto-lock time (Settings → Security → Auto-lock).
- Force-close the app from Recents.
- Relaunch.
Expected
- Quick background: app stays open.
- After timeout: app is locked.
- After force-close: next start is always locked.
Result
Status: ✅ PASS
Comments:
A5 ✅ PASS
Biometric Unlock + Invalidation
Steps
- Enable Settings → Security → Biometric unlock.
- Lock the database.
- Unlock using fingerprint/face.
- Go to Android system settings and enroll an additional fingerprint.
- Return to the app.
Expected
- Biometric unlock works in step 3.
- After enrolling new fingerprint: app refuses biometrics with an explanation ("biometrics were reset…"), requires master password, database remains fully intact.
- Can re-enable biometric unlock afterwards.
Result
Status: ✅ PASS
Comments:
A6 ❌ FAIL
Clipboard
Steps
- Copy a password from the detail view.
- Check if a countdown notification appears (Android 13+: grant notification permission if asked).
- Paste the password in another app — confirm it works.
- Wait 30 seconds; attempt to paste again.
- Try the "Clear now" button in the notification.
- Check the keyboard's own clipboard history (Samsung/Gboard/SwiftKey).
Expected
- Countdown notification appears immediately.
- Password can be pasted within 30 seconds.
- After 30 seconds: password can no longer be pasted (usernames/URLs: 60 s).
- "Clear now" clears immediately.
- Note: keyboard clipboard history (outside the app's control) may still show the value — document this, do NOT report as a bug.
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
A7 ✅ PASS
Autofill in Your Daily Browser
Note: ⚠️ Chrome 131+ extra step required: Chrome → Settings → Autofill services → "Autofill using another service" → restart Chrome.
Steps
- Enable Settings → Autofill service (follow system dialogs).
- Open Settings → Autofill test; confirm the suggestion appears on the built-in test form.
- Navigate to a test account login page in your browser.
- Verify autofill suggestion appears (inline chip or system sheet).
- Fill with Password Depot; confirm fields are filled correctly.
- Log in with a new credential typed manually; confirm save/update prompt appears.
- Negative check: navigate to a different or look-alike domain; confirm the entry is NOT offered under "Matching this site".
Expected
- Suggestion appears on matching domain.
- Save/update flow works.
- No suggestion offered for non-matching domains.
Result
Status: ✅ PASS
Comments:
A8 ✅ PASS
Autofill in One App
Steps
- Open any app with a login screen (use a test account).
- Trigger autofill.
- Test an app using Android Credential Manager (e.g. Facebook) if available.
Expected
- Autofill works or cleanly offers nothing — no crash, no wrong entry offered.
- Credential Manager apps: system sheet offers the matching entry when Digital Asset Links are published; otherwise "No entry for …" message (no crash).
Result
Status: ✅ PASS
Comments:
A9 ❌ FAIL
Appearance, Language, Rotation, Tablet
Steps
- Switch appearance: dark → light → system mode.
- Switch app language DE ↔ EN (Settings → App language on Android 13+).
- Rotate the device while unlocked; confirm session and selection survive.
- (Tablet/foldable only) Verify the two-pane list+detail layout.
- Note any clipped, untranslated, or oddly-worded text.
Expected
- All appearance/language switches work without restart.
- Rotation preserves state.
- Two-pane layout is correct on tablets.
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
A10 ❌ FAIL
Stability & Error Visibility
What to test: What to watch for throughout testing: any crash or ANR (app not responding); any freeze that requires a force-close; any error that is swallowed silently (action appears to work but data is wrong).
Steps
- If any of the above occur, open Support data immediately (lock → "Support data…" on unlock screen).
- Copy the version line and any listed events.
- File a Jira Bug with Sev-0 and attach the support data.
Expected
- No crashes, freezes, or silently swallowed errors.
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
Part 3 — Focus Blocks C1–C11
Complete the blocks assigned to you, or any you have the setup for.
C1 ✅ PASS
TOTP
Setup needed: A test account with 2FA / TOTP setup, and a reference authenticator app.
Steps
- Add a TOTP secret to a test entry using the entry editor.
- In Round 13: use "Scan QR code" (camera or photo) to add the TOTP secret — test the new QR scanner.
- Compare the 6-digit code with a reference authenticator for at least 3 consecutive periods.
- With autofill: open the 2FA field on a login page; confirm the code is offered only into the one-time-code field.
- Confirm the code is never offered into user/password fields.
Expected
- Codes match the reference authenticator for ≥3 periods.
- Code offered only into OTP fields.
- QR scanner works with camera and photo; invalid QR code rejected with message.
Result
Status: ✅ PASS
Comments:
C2 ✅ PASS
Passkeys (Android 14+)
Setup needed: Android 14+, device screen lock enabled. Test site: https://webauthn.io
Steps
- Settings → Passkey provider → select Password Depot. Verify the row shows "Enabled".
- On webauthn.io: register a new passkey (should land in the Password Depot database).
- Sign in with the passkey using the same database.
- Move the passkey entry to the trash.
- Attempt sign-in again → expect "No matching passkey in the database".
- Restore the passkey entry.
- Attempt sign-in again → confirm it works.
Expected
- All steps above behave as described.
- If sign-in fails at any point, attach the support bundle.
Result
Status: ✅ PASS
Comments:
C3 ❌ FAIL
WebDAV Sync
Setup needed: A real Nextcloud and/or Apache WebDAV server over HTTPS.
Steps
- Link the WebDAV server (Settings → Storage location & sync).
- Perform the initial database upload.
- Edit an entry on Android; sync; verify on Windows.
- Edit the same entry on both Android and Windows simultaneously.
- Sync from Android.
Expected
- Initial upload succeeds.
- Single-side edits merge without data loss.
- Concurrent edit on same entry: a conflicted copy appears on Android; original is untouched; conflict can be marked as resolved; nothing lost silently.
- Note the server product + version and whether the account reports safe concurrent writes.
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22
Comments:
C4 ✅ PASS
Windows Interop
Setup needed: Windows Password Depot 19 and the same database accessible on both (file copy or WebDAV).
Steps
- Open the same .pswe file alternately in Windows PD 19 and Android.
- Verify that the following survive both directions (Android→Windows, Windows→Android): entries with umlauts/emoji in titles, folders and sub-folders, attachments, TAN lists (kept in file even though Android does not display them), entry history, custom icons, second-password ("four eyes") entry.
- Specifically: set an expiry date on Android; open in Windows; confirm the date is preserved.
- Edit the same entry on both sides; sync; confirm a conflict copy appears rather than a silent overwrite.
Expected
- All content survives both directions unchanged.
- Any Windows-visible difference is a top priority report.
Result
Status: ✅ PASS
Comments:
C5 ✅ PASS
Attachments
Steps
- Attach a photo (a few MB) to an entry; reopen and export it; verify the file is intact.
- Attach a PDF (a few MB) to an entry; reopen and export it; verify the file is intact.
- Attempt to attach a file over 25 MB.
Expected
- Photo and PDF attach, export, and open correctly.
- File over 25 MB: refused with a clear message, no crash.
Result
Status: ✅ PASS
Comments:
C6 ✅ PASS
Multi-Database & Master Password Change
Steps
- Create a second database; switch between both databases.
- "Remove from app" on one database; confirm the database file still exists and can be re-added.
- Change the master password of a test database.
- Attempt to unlock with the old password.
- Check biometric unlock status.
Expected
- Switching between databases works seamlessly.
- "Remove from app" does not delete the file.
- Old password is rejected after change.
- Biometric unlock requires re-enabling after a password change.
Result
Status: ✅ PASS
Comments:
C7 ✅ PASS
Backup & Restore
Steps
- Navigate to Databases & sync → Backup copies; create a backup of a test database.
- Make a few changes to the database.
- Restore an earlier backup copy.
- Enter a wrong password during restore; check for throttle (3 s / 10 s delay) and message.
- Enter the correct password; confirm restore.
- Verify the restored state is complete; confirm the previous state was saved as a new backup copy first; confirm the chosen copy is still listed.
- (If database is linked to a storage source) Confirm a notice says the next sync will merge instead of replace.
- Attempt to restore a deliberately corrupted backup file.
Expected
- Correct password restores successfully; current state saved before restore; chosen backup still listed.
- Wrong password: throttle + clear message.
- If linked to storage: merge notice shown.
- Corrupted backup: refused with error; active database untouched.
Result
Status: ✅ PASS
Comments:
C8 ✅ PASS
Enterprise Thin Client
Setup needed: Office test server (Enterprise Server 20).
Steps
- Open the app → "Enterprise server…" on the start screen.
- Enter the server address and port; log in.
- On first connect: verify the TLS fingerprint confirmation dialog appears. Compare the SHA-256 with the server certificate (Windows: Home → PD Enterprise Server → "View server certificate").
- Confirm server and port are remembered after the first successful login.
- Browse and search entries on the server.
- Edit an entry and save.
- Test sign-in with Windows domain credentials (DOMAIN\user or user@company.com) if AD is available.
Expected
- TLS fingerprint dialog appears on first connect.
- Login succeeds; server/port remembered.
- Browse, search, and edit work.
Result
Status: ✅ PASS
Comments:
C9 ⏭️ SKIP
Enterprise Offline Copy
Setup needed: Enterprise Server 20, TCP port 25020, a database with the offline right granted.
Steps
- Sign in to the server; tap "Save offline copy…" on the database list.
- Enter the server password (2FA accounts get a code field in step 2).
- Tap "Load databases" — confirm the TLS fingerprint once.
- Pick a database; confirm the copy is saved.
- Sign out; tap "Open offline copy" on the login screen; open with the server password.
- Verify the status line reads "Enterprise Server · offline copy".
- Create/edit an entry offline; note the waiting-changes counter in the status line.
- Settings → Sync… → "Send changes to the server": certificate question appears inside this screen; enter fingerprint; confirm all changes sent; "Load fresh copy" offered.
- Check: entry the server marks as non-editable → no edit action shown.
- Check: without export/save-as rights → Export and "Save as" are absent.
- Check: "Usable until" date matches the server's offline period.
- Check: offline copy cannot be linked to cloud/WebDAV storage.
- Enter a wrong server password for an existing copy; confirm the error names the password (not "changes waiting").
Expected
- All steps above behave as described.
- Report the server version from its console with any failure.
Result
Status: ⏭️ SKIP
Comments:
C10 ✅ PASS
Enterprise Single Sign-On (OpenID Connect / Entra ID)
Setup needed: Enterprise Server 20 with a configured OpenID Connect or Entra ID sign-in provider; the provider registration must contain the redirect oidc.acebit://password-depot.de/.
Steps
- Choose "Single sign-on (OpenID Connect / Entra ID)" in the Enterprise login; tap "Connect".
- Complete sign-in in the browser; confirm the app returns to the database list.
- Sign out; use "Sign in with a different account"; confirm the provider prompts for account selection.
- Start a sign-in and cancel it in the browser; confirm the app shows "The sign-in in the browser was cancelled".
- Sign in with an account the server does not know; expect "The Enterprise Server did not accept the sign-in…".
- Rotate the device while the browser is open; confirm the sign-in continues.
- Press Home during sign-in and return via the browser.
- (If configured) Test the second factor after sign-in.
Expected
- All scenarios above behave as described.
- Report: provider type (Entra ID or other), server version (19 or 20), and exact error messages.
Result
Status: ✅ PASS
Comments:
C11 ⏭️ SKIP
Hand-Over of Previous-App Offline Changes
Setup needed: Enterprise Server 20, TCP port 25020. Either a previous-app installation with unsent offline changes, or the prepared file from the dev team.
Steps
- Start with the previous Password Depot for Android app installed and an Enterprise database with unsent offline changes.
- Update to this build; open "Import from previous app"; take the database over.
- Verify the report names the number of unsent changes and says they can be sent from the database.
- "Unlock now": confirm the note at the top shows the same number.
- Tap "Send to the server…": port 25020 and database name pre-filled; enter server, account, password.
- On first contact: certificate fingerprint question appears inside the dialog — enter it.
- Confirm the note disappears and the changes are on the server (verify in the Windows client).
- Test with a rejected change (e.g. no delete permission): note stays and names the reason; a later send tries only remaining open changes.
- Confirm the database never silently loses the note.
Expected
- All steps above behave as described.
Result
Status: ⏭️ SKIP
Comments:
5 · Device Matrix Contribution
| Dimension | Variant | Covered | Notes |
|---|
| Keyboard |
Gboard |
✅ |
|
| Keyboard |
Samsung Keyboard |
✅ |
|
| Keyboard |
SwiftKey |
✅ |
|
| Browser |
Chrome |
✅ |
|
| Browser |
Edge |
❌ |
https://internal.tracker.password-depot.de/browse/AC-493 |
| Browser |
Firefox |
✅ |
|
| Browser |
Samsung Internet |
❌ |
https://internal.tracker.password-depot.de/browse/AC-494 |
| Autofill style |
Android 11+ inline chips (note which you saw) |
— |
|
| Autofill style |
Android ≤13 dropdown |
✅ |
|
| Clipboard |
Samsung clipboard behavior |
❌ |
https://internal.tracker.password-depot.de/browse/AC-475 |
| Clipboard |
Pixel clipboard behavior |
✅ |
|
| Clipboard |
Xiaomi clipboard behavior |
❌ |
https://internal.tracker.password-depot.de/browse/AC-524 |
| Biometrics |
Fingerprint |
✅ |
|
| Biometrics |
Face unlock |
✅ |
|
| Biometrics |
Both enrolled |
n/a |
No real device for testing. |
| OEM quirks |
Xiaomi/HyperOS battery saver — auto-lock reliable? |
n/a |
No real device for testing. |
| OEM quirks |
Samsung battery saver — session killed mid-edit? |
✅ |
|
| Form factor |
Phone |
✅ |
|
| Form factor |
Tablet (≥ 600 dp) |
✅ |
|
| Form factor |
Foldable |
n/a |
No device |
6 · Reporting Reference
| Jira Project | Android Client (AC) |
| Issue Type (bugs) | Bug |
| Issue Type (coverage) | Task |
| Affects Version | 20.0.0 |
| Build line | 20.0.0-beta13 (1943) |
| Severity 0 | crash · data loss · lock-out |
| Severity 1 | feature wrong or unusable |
| Severity 2 | wrong, has a workaround |
| Severity 3 | visual / text |
| Deadline | within 10 working days |
| Bug summary format | <area>: <short title> |
| Coverage summary format | Beta coverage: <device> |
Support data: lock the app → tap "Support data…" on the unlock screen. Strictly local, secret-free. Copy version line + events into the issue.