Password Depot for Android — QA Test Report

Build 20.0.0-beta21 (1951) · Round 17 · Merged with 20.0.0-beta17 (1947) / Round 16 · Generated 9/21/2026, 7:35:17 PM

1 · Environment

Device / AndroidSamsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
KeyboardSamsung Keyboard 5.9.12, Microsoft SwiftKey, Gboard
Browser(s)Chrome 152, Edge 152, Firefox 155
Build line20.0.0-beta21 (1951)
TesterSheva Ma
Date started2026-Sep-21

2 · Summary

BlockTotal✅ Pass❌ Fail🚫 Blocked⏭️ Skip🔄 In Progress⬜ Pending
Part 0 — Round 17 Re-Test: Beta17 Bug Fixes 1172 00 20
Part 0b — Round 17 Audit Fix Wave (visible items) 1200 00 111
Part 0c — Round 16 Re-Test: Beta15 Bug Fixes (historical) 11101 00 00
Part 0d — Round 16 New Features (beta17) (historical) 1080 20 00
Part 0e — Round 14 Re-Test: Beta13 Bug Fixes (historical) 13130 00 00
Part 1 — Core Pass: A1–A10 (Every Tester, Every Device) 10100 00 00
Part 3 — Focus Blocks C1–C11 1162 30 00
Total78545 50 131
Items tested / total59 / 78
Pass rate (of decided items)92%
Failures (checklist items)5
Blocked items5
New bugs discovered (manual entry)2
Skipped0

3 · Failures (5)

R17-4 AC-480 Entries protected with a second password are recognised in the autofill picker
Section: Part 0 — Round 17 Re-Test: Beta17 Bug Fixes
Tested device: Galaxy S22, Android 15
Comments / Jira key: I’m able to see the entry list now, but once I click the entry, nothing happens, please check below screen recording.
R17-9 AC-543 New storage locations: FTPS/FTPES and HiDrive
Section: Part 0 — Round 17 Re-Test: Beta17 Bug Fixes
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-609
S8 AC-493 / AC-494 Pinned browser without a web address is no longer treated as a native app
Section: Part 0c — Round 16 Re-Test: Beta15 Bug Fixes (historical)
Tested device: Android 14 on Galaxy S24 Ultra
Comments / Jira key: AC-494 still reproducible.
C1 TOTP
Section: Part 3 — Focus Blocks C1–C11
Tested device: Galaxy S22, Android 15
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-537
C10 Enterprise Single Sign-On (OpenID Connect / Entra ID)
Section: Part 3 — Focus Blocks C1–C11
Tested device: Galaxy S22, Android 15
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-608

3a · New Bugs Discovered (Manual Entry) (2)

Bugs entered manually during this round; not part of the fixed checklist. One finding per entry — copy the Jira key into the tracker.

NEW #1 AC-608 Sev-2 SSO / OpenID Connect login fails on Android client when 2FA is enabled on Enterprise Server
Tested device: Galaxy S22, Android 15
Description / Steps to reproduce:
Environment:
Client: Android Client (v20.0.0 Beta 21)
Android 15, Samsung Galaxy S22.
Connection: Enterprise Server (Port: 8714, Sign-in method: Single sign-on (OpenID Connect / Entra ID))

Steps to Reproduce:
1. Enable Two-Factor Authentication (2FA) on the Password Depot Enterprise Server.
2. Open Android client and navigate to "Connect to Enterprise Server".
3. Enter Server address and Port (e.g., 8714).
4. Select Sign-in method: "Single sign-on (OpenID Connect)".
5. Tap "Connect" and complete the company account (Entra ID / OpenID Connect) sign-in in browser.

Expected Result:
Login succeeds or prompts for required 2FA / TOTP second-factor verification as expected.

Actual Result:
Sign-in fails with error message:
"The Enterprise Server did not accept the sign-in. Your account may not be linked to this sign-in service yet."
NEW #2 AC-609 Sev-2 WebDAV/HiDrive DB: URL contains "#$" causes UI validation error; error message incorrect even when URL ends with .pswe
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Description / Steps to reproduce:
Problem
When opening a WebDAV (Strato HiDrive) database, if the URL contains the characters #$, the UI immediately shows an error/validation state. The error message is misleading/incorrect: it complains that the address must end with a file name (e.g. database.pswe) even though the provided URL already ends with .pswe.

Steps to reproduce
1. In Android app, go to Open from WebDAV server.
2. Choose service Strato HiDrive (or open WebDAV/HiDrive DB flow).
3. In WebDAV file URL, paste a URL that contains #$ anywhere in the URL (and still ends with .pswe).
Observe the UI shows an error immediately.

Actual result
UI shows validation error state.
Error message shown: "The address must end with the file name (e.g. database.pswe)."

Expected result
URL validation should accept URLs that include special characters like #$ (or properly percent-encode/handle them), as long as the URL is otherwise valid and ends with .pswe.

If the URL is invalid, the UI should show a correct error message explaining the real problem (e.g., invalid characters / must be URL-encoded).

3b · Blocked Items (5)

Items that could not be executed at all — missing test environment, missing server build, no hardware, etc. Each entry names the blocker.

T1 AC-508 Entries with a second password can be edited again
Section: Part 0d — Round 16 New Features (beta17) (historical)
Environment / blocker info: Galaxy S22, Android 15
Blocker / Comments: I can edit the entry that includes the second password, but adding a new entry doesn't include the second password field. The field is required to connect to Enterprise Server v20.0.0. Since ES v20 isn't ready for testing, leave this for now and verify again once ES v20 is ready.
T8 AC-512 Server editor: TOTP set / change / remove
Section: Part 0d — Round 16 New Features (beta17) (historical)
Environment / blocker info: Galaxy S22, Android 15
Blocker / Comments: No Enterprise server build for testing, then will verify it once Enterprise server is ready.
C8 Enterprise Thin Client
Section: Part 3 — Focus Blocks C1–C11
Environment / blocker info: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Blocker / Comments: Enterprise Server v20 is not ready for testing.
C9 Enterprise Offline Copy
Section: Part 3 — Focus Blocks C1–C11
Environment / blocker info: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Blocker / Comments: Enterprise Server V20 is not ready for testing.
C11 Hand-Over of Previous-App Offline Changes
Section: Part 3 — Focus Blocks C1–C11
Environment / blocker info: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Blocker / Comments: Enterprise Server v20 is not ready for testing.

4 · Detailed Results

Part 0 — Round 17 Re-Test: Beta17 Bug Fixes

These bugs were reported in Round 16 and claimed fixed in beta21. Re-test every one on build 1951.

R17-1AC-539Sev-1 ✅ PASS
Firefox shows “Fill in with Password Depot” again
What to test: Firefox stopped showing the autofill suggestion in Round 16. The fix restores “Fill in with Password Depot”.
Steps
  1. Enable Settings → Autofill service.
  2. Open a login page in Firefox with a saved matching entry.
  3. Trigger autofill / tap in the login field.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-2AC-538Sev-2 ✅ PASS
Server DB: manually loaded entries stay listed while search box is empty
What to test: With an Enterprise Server database, entries loaded manually stayed listed when the search box was empty. Partial fix: the full Edge case stays open.
Known issue / note: Partial fix — the full Edge case stays open. Please report separately if the Edge variant still fails.
Steps
  1. Open an Enterprise Server database in the app.
  2. Trigger autofill; load entries manually.
  3. Clear the search box and observe whether the entries remain listed.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-3AC-540Sev-3 ✅ PASS
Permanent setup banner on Android 14 no longer sticks
What to test: The permanent autofill setup banner on Android 14 stayed visible. Partial fix.
Known issue / note: Partial fix.
Steps
  1. Set up autofill on Android 14.
  2. Dismiss the setup banner.
  3. Navigate back to the home screen.
Expected
Result
Status: ✅ PASS
Tested device: Galaxy S22, Android 15
Comments:
— none —
R17-4AC-480Sev-1 ❌ FAIL
Entries protected with a second password are recognised in the autofill picker
What to test: The autofill picker now explains why the password or one-time code is not handed out, and you can pick another entry.
Steps
  1. Create an entry with a second password.
  2. Trigger autofill on a matching site.
  3. Tap the protected entry in the picker.
Expected
Result
Status: ❌ FAIL
Tested device: Galaxy S22, Android 15
Comments:
I’m able to see the entry list now, but once I click the entry, nothing happens, please check below screen recording.
R17-5AC-541Sev-1 ✅ PASS
Clipboard countdown no longer loops; clipboard is really cleared
Setup needed: Galaxy S26 Ultra / Android 16 (Sheva please re-test).
What to test: The countdown looped from 30 s to 1 s forever, and the clipboard was not actually cleared.
Steps
  1. Copy a password from the detail view.
  2. Observe the countdown notification.
  3. Wait until the countdown reaches zero.
  4. Attempt to paste the password in another app.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-6AC-517Sev-1 ✅ PASS
Passkeys on a server database stay in that database
What to test: Creating a passkey while a server database is active now stores it in that database — before, it silently went into the previously opened local file.
Steps
  1. Open a server database in the app.
  2. Create a passkey on a website (webauthn.io or another test site).
  3. Check in which database the passkey landed.
  4. Switch to the local database and check there too.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-7AC-542Sev-2 ✅ PASS
Entry icons for types without a URL field
What to test: Entry types without a URL field (nine types) can load an icon from a web address typed in the icon picker; the field is prefilled with the entry’s address where one exists.
Steps
  1. Open an entry type without a URL field (e.g. Identity, Information, PuTTY).
  2. Open the icon picker.
  3. Type a web address; load the icon.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-8AC-544Sev-1 🔄 IN PROGRESS
Settings taken over from the old app (needs 19.x migration)
Setup needed: A real 19.x installation to migrate from.
What to test: The takeover now brings the lock timeout, appearance, and master-password policy; biometric unlock is offered per database after the first unlock instead of being copied. Olha’s ten steps are in AC-602.
Steps
  1. Install a 19.x build with custom lock timeout, appearance, and master-password policy.
  2. Update to this build and run “Import from previous app”.
  3. Check the takeover report.
  4. Verify lock timeout, appearance, master-password policy.
  5. Verify biometric unlock is offered per database after first unlock.
Expected
Result
Status: 🔄 IN PROGRESS
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments:
— none —
R17-9AC-543Sev-1 ❌ FAIL
New storage locations: FTPS/FTPES and HiDrive
Setup needed: Your own FTPS server, or ask for the test server.
What to test: An FTPS or FTPES server can hold a database like WebDAV does, with a certificate-fingerprint question on first contact. HiDrive is its own entry in the provider list. Plain FTP is NOT offered (as in Windows 20).
Steps
  1. Open “Open from cloud…” or “Storage location & sync”.
  2. Add an FTPS/FTPES server.
  3. On first contact, compare the certificate fingerprint question.
  4. Verify the fingerprint matches the server’s.
  5. Add HiDrive as a provider; verify the row says “HiDrive”.
  6. Verify OneDrive row says “personal or business account (OneDrive for Business)”.
  7. Verify no plain FTP option exists.
Expected
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments:
https://internal.tracker.password-depot.de/browse/AC-609
R17-10AC-458Sev-3 ✅ PASS
Language: Early Android 15 no longer keeps Chinese texts
Setup needed: Galaxy S22 / One UI 7 confirmation wanted.
What to test: Early Android 15 could keep Chinese texts after switching the system language back to English; English texts are now explicit resources.
Steps
  1. Set system language to Chinese.
  2. Set app language to English.
  3. Switch system language back to English.
  4. Observe app texts.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-11AC-545Sev-1 🔄 IN PROGRESS
Invisible: Intune app protection SDK (dormant)
What to test: The Microsoft Intune SDK is back in the app as in 19.x. It is dormant without a company setup and there is no menu entry yet; nothing should look or behave differently.
Steps
  1. Note start-up time and behaviour on first launch.
  2. Use autofill, passkeys and normal flows.
  3. Watch for any unexpected network or sign-in prompt.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —

Part 0b — Round 17 Audit Fix Wave (visible items)

Two independent code reviews on 19 Sep produced 56 findings; all but one are fixed (AC-546 to AC-601, AC-576 was no error). These are the ones you can see. Each ticket names its own steps in Jira — sample them.

AUD-1AC-546 / AC-585 / AC-597 🔄 IN PROGRESS
Documents keep the right encryption mode
What to test: Documents keep the right encryption mode after a master-password change or a mode switch.
Steps
  1. Create a document entry.
  2. Change the master password.
  3. Switch the encryption mode (if applicable).
  4. Reopen the document and verify the file is intact.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
AUD-2AC-547 / AC-548 ⬜ PENDING
Second-password entries keep custom fields when edited
What to test: Entries with a second password keep their custom fields when edited.
Steps
  1. Create an entry with a second password and a custom field.
  2. Unlock with the second password; edit a field; save.
  3. Reopen and verify the custom field is intact.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
AUD-3AC-549 / AC-556 / AC-557 / AC-591 🔄 IN PROGRESS
SSO offline copies stay usable; require fresh provider sign-in
What to test: SSO offline copies keep their backups usable and open only after a fresh provider sign-in, never by biometrics alone.
Steps
  1. Save an offline copy while signed in with SSO.
  2. Sign out; attempt to open the offline copy.
  3. Observe the required sign-in.
  4. Check that backups of the copy are still usable.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
AUD-4AC-587 / AC-588 / AC-589 / AC-601 🔄 IN PROGRESS
Switching database slot during sync no longer writes into the other database
What to test: Switching the database slot during a running sync, journal or offline operation no longer writes into the other database.
Steps
  1. Start a sync / journal / offline operation on database A.
  2. While it is running, switch to database B.
  3. Verify that no writes leaked into database B.
  4. Return to database A and confirm the operation completed correctly.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
AUD-5AC-590 🔄 IN PROGRESS
Foreign database at same cloud path does not break the slot
What to test: A foreign database at the same cloud path no longer breaks the slot.
Steps
  1. Place a non-Password-Depot file at the same cloud path.
  2. Open the slot in the app.
  3. Observe the error handling.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
AUD-6AC-595 / AC-596 / AC-560 🔄 IN PROGRESS
Server passkeys stop after sign-out; bad challenge rejected properly
What to test: Server passkeys stop after sign-out and reject a bad challenge with a proper error. A protected server passkey no longer blocks unprotected matches.
Steps
  1. Create a passkey on a server database.
  2. Sign out from the server.
  3. Attempt a passkey sign-in — should fail with a proper error.
  4. Have a protected and an unprotected passkey for the same site; verify the unprotected one is still offered.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
AUD-7AC-567 / AC-568 / AC-569 🔄 IN PROGRESS
Rotating device during a system dialog keeps state
What to test: Rotating the device during a system dialog keeps category changes, the file-picker target and the document export.
Steps
  1. Open a system dialog (category change, file picker, document export).
  2. Rotate the device.
  3. Complete the dialog and verify the state was preserved.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
AUD-8AC-573 / AC-578 / AC-570 🔄 IN PROGRESS
Server search shows waiting state; SSO user name in status; custom field shows new value
What to test: The server search shows a waiting state instead of stale results, the status line shows your user name after SSO, and a saved custom field shows its new value.
Steps
  1. Run a server search and observe the waiting state.
  2. Sign in with SSO and check the status line.
  3. Edit a custom field, save, reopen and verify the new value.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
AUD-9AC-562 / AC-563 / AC-559 🔄 IN PROGRESS
Export blocked by policy says so; full device named; long passwords warned
What to test: An export blocked by policy says so, a full device is named as the cause, and long passwords are no longer silently cut to 512 characters — you get a notice.
Steps
  1. Attempt an export blocked by MDM policy.
  2. Attempt an export on a full device.
  3. Enter a very long password (>512 characters) and save.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
AUD-10AC-586 / AC-582 / AC-581 🔄 IN PROGRESS
Backups browsable; recycle bin reachable in large DBs; lists easier to navigate
What to test: Backups can be browsed and old entries viewed before restoring, the recycle bin is reachable in large databases, and very long lists are easier to navigate (fast-scroll handle deferred).
Steps
  1. Open a backup and browse entries before restoring.
  2. Open the recycle bin in a large database.
  3. Scroll a very long list and use the navigation aids.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
AUD-11AC-566 / AC-579 / AC-583 🔄 IN PROGRESS
Cloud write unverified reported; external backup streams; server autofill asks one question
What to test: A cloud write that could not be verified is reported as exactly that instead of “rejected, HTTP 200”; the external backup copy streams instead of loading the whole file into memory; server autofill after a session end asks one plain question with two options.
Steps
  1. Trigger a cloud write that cannot be verified.
  2. Create an external backup copy of a large database.
  3. End a server session and trigger autofill.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
AUD-12AC-580 / AC-564 / AC-565Sev-3 🔄 IN PROGRESS
Takeover wording unified; FAQ corrected
What to test: The takeover wording is unified and the FAQ corrected.
Steps
  1. Open the takeover screen and the FAQ.
  2. Check for consistent wording.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —

Part 0c — Round 16 Re-Test: Beta15 Bug Fixes (historical)

These bugs were reported in Round 14 and claimed fixed in beta17. Kept for regression coverage — re-test if you have the setup or if the round-17 list touches the same area.

S1AC-523Sev-1 ✅ PASS
An expired Enterprise Server session really ends the session
What to test: After ten minutes without server traffic you are taken back to the sign-in screen instead of still being able to open and copy entries.
Steps
  1. Sign in to Enterprise Server.
  2. Wait ~10 minutes without server traffic (or trigger an expired-session state).
  3. Try to open or copy an entry.
  4. Open the editor, make a change, wait for expiry, then attempt to save.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S2AC-526Sev-1 ✅ PASS
Unlocking a local or cloud database makes autofill use it
What to test: Unlocking a local or cloud database now makes autofill use it instead of the last server database.
Steps
  1. First open an Enterprise Server database, then lock it.
  2. Unlock a local or cloud database.
  3. Trigger autofill in a browser.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S3AC-527 ✅ PASS
Cloud account shows as connected right after sign-in
Steps
  1. Open Settings → Databases & sync → Cloud accounts.
  2. Sign in to a cloud provider.
  3. Return to Cloud accounts.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S4AC-530 ✅ PASS
“File already exists” appears immediately when picking an existing database
Steps
  1. Open from cloud / Open database file… and pick a file that already exists in the app.
  2. Observe the timing of the “File already exists” message.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S5AC-480 ✅ PASS
Server entry protected by a second password is marked in autofill
Steps
  1. Create a server entry with a second password.
  2. Trigger autofill on a matching site.
  3. Tap the marked entry.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S6AC-487 ✅ PASS
Category picker in the server editor offers the categories
Steps
  1. Open a server entry in the editor.
  2. Open the category picker.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S7AC-458Sev-3 ✅ PASS
App language wraps all 14 windows (incl. autofill and passkey dialogs)
Setup needed: Galaxy S22 with system language in Chinese.
Steps
  1. Set the app language to a non-system language.
  2. Open the autofill window and the passkey dialogs.
  3. Verify all text follows the app language.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S8AC-493 / AC-494 ❌ FAIL
Pinned browser without a web address is no longer treated as a native app
Setup needed: Edge and Samsung Internet installed and pinned.
Steps
  1. Open Edge or Samsung Internet with no web address.
  2. Trigger autofill.
Expected
Result
Status: ❌ FAIL
Tested device: Android 14 on Galaxy S24 Ultra
Comments:
AC-494 still reproducible.
S9AC-517 ✅ PASS
Passkeys of an open Enterprise Server database are offered before the local ones
Setup needed: Chrome 131 or newer.
Steps
  1. Open the Enterprise Server database in the app.
  2. Trigger a passkey sign-in in Chrome 131+ on a site matching both databases.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S10AC-522Sev-3 ✅ PASS
Server mode navigation rail: first item is “Home”, no search
Steps
  1. Switch to server mode on a tablet (or wide layout).
  2. Observe the navigation rail.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S11AC-524Sev-0 ✅ PASS
Home screen no longer reads autofill setup state without a safety net (Xiaomi crash)
Setup needed: Xiaomi device.
Steps
  1. Open the app on a Xiaomi device.
  2. Check for any crash on the home screen.
  3. If it crashes, attach the device log.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 0d — Round 16 New Features (beta17) (historical)

New in beta17. Kept for regression coverage.

T1AC-508Sev-0 🚫 BLOCKED
Entries with a second password can be edited again
What to test: Unlock a protected entry with its second password; it edits like any other entry. A new row Second password lets you set / change / remove it. The dialog says plainly that there is no recovery.
⭐ Big feature: ⭐ THE BIG ONE from Round 16 — the previous Android app 19.x could do this; 20.0.0 could not until beta17.
Steps
  1. Open an entry with a second password.
  2. Unlock it with its second password.
  3. Edit its user name and/or password.
  4. Save; verify values go back under the same second password without asking again.
  5. On an unprotected entry: set a second password (enter twice), then change it, then remove it.
  6. Open the same database in Password Depot for Windows and check the entry there.
Expected
Result
Status: 🚫 BLOCKED
Environment / blocker info: Galaxy S22, Android 15
Comments:
I can edit the entry that includes the second password, but adding a new entry doesn't include the second password field. The field is required to connect to Enterprise Server v20.0.0. Since ES v20 isn't ready for testing, leave this for now and verify again once ES v20 is ready.
T2AC-528 / AC-529Sev-1 ✅ PASS
Cloud accounts — account switch end to end
What to test: Cloud accounts list shows every connected provider with its account and a Sign out. Signing out disconnects and revokes the token; the next sign-in lets you pick a different account. A database stays with the cloud account it was linked to.
Steps
  1. Open Settings → Databases & sync → Cloud accounts.
  2. Sign out a connected provider.
  3. Sign in again; verify the provider lets you pick a different account.
  4. Open a database of account 1 while account 2 is connected.
  5. Reproduce with Dropbox, OneDrive, and Google Drive.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T3AC-514 / AC-510 ✅ PASS
Entry editor — pinned Save header + Symbol row after URL rows
Steps
  1. Open a long form entry editor and scroll to the bottom.
  2. Verify the Save header stays pinned.
  3. For a type with URLs: verify the Symbol row sits after the URL rows.
  4. For a type without URLs: verify the Symbol row is where it was.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T4AC-534Sev-0 ✅ PASS
Key files — unlock always asks explicitly (no silent copies)
Setup needed: A database protected by a key file.
What to test: A normal unlock now always asks for the key file explicitly; the app no longer keeps or creates silent copies of it. Exporting a key file is read back after writing and obeys the export policy.
Steps
  1. Unlock a key-file-protected database.
  2. Verify the app asks for the key file explicitly.
  3. Check Settings for any stored key-file copy; revoke if present.
  4. Export a key file; verify the file is read back and the export policy is obeyed.
  5. Test unlock, backup and restore.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T5AC-532Sev-3 ✅ PASS
Unlock error messages with a key file
Steps
  1. Attempt unlock with a wrong key file only.
  2. Attempt unlock with a wrong password plus a key file.
  3. Attempt unlock with a wrong password only.
  4. Repeat the same in the autofill window and the passkey dialog.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T6AC-477 ✅ PASS
Autofill can optionally keep one unlock for a short while (OFF by default)
Design: true
Steps
  1. Turn the option on in the settings.
  2. Authenticate once; fill an entry.
  3. Fill another entry within the window; verify no re-auth prompt.
  4. Wait past the window; verify re-auth is required.
  5. Lock the device or app; verify the window is revoked immediately.
  6. Turn the option back off (default).
Expected
Result
Status: ✅ PASS
Comments:
— none —
T7AC-468Sev-1 ✅ PASS
Entry layouts now follow the Windows client
Setup needed: Windows Password Depot 20 with the same database.
Steps
  1. Open a local entry and a server entry of the same type side by side with Windows.
  2. Compare field order and grouping per type.
  3. Open a Banking entry; verify expiry is MM/YYYY.
  4. Add a field the app does not know on Windows; save on Android; verify it is preserved.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T8AC-512Sev-1 🚫 BLOCKED
Server editor: TOTP set / change / remove
Setup needed: Enterprise Server with ES-990.
Steps
  1. Open a server entry in the editor.
  2. Set a TOTP secret; save.
  3. Change the TOTP secret; save.
  4. Remove the TOTP secret; save.
  5. Open an unsaved server entry; verify TOTP setup only appears after the first save.
Expected
Result
Status: 🚫 BLOCKED
Environment / blocker info: Galaxy S22, Android 15
Comments:
No Enterprise server build for testing, then will verify it once Enterprise server is ready.
T9AC-535 / AC-533Sev-2 ✅ PASS
Cloud accounts — Dropbox real name + account mismatch notice
Steps
  1. Sign in to Dropbox; verify the real account name is shown.
  2. Trigger an account mismatch; verify the notice can be dismissed.
  3. Trigger an unlock error; switch database slots or go to settings; verify the error disappears.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T10AC-497Sev-2 ✅ PASS
Enterprise sign-in — precise e-mail messages keep wording under SSO
Setup needed: Enterprise Server with an SSO-configured sign-in provider.
Steps
  1. Attempt sign-in with an unknown e-mail address under SSO.
  2. Attempt sign-in with a blocked e-mail address under SSO.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 0e — Round 14 Re-Test: Beta13 Bug Fixes (historical)

These bugs were reported in Round 13 and claimed fixed in beta15. Kept for regression coverage.

R1AC-496Sev-0 ✅ PASS
Crash “Placement happened before lookahead” in list/detail layout
Steps
  1. Repeat both step sequences from the original report on a Galaxy S22 with a cloud database.
  2. Open the list, open a detail, navigate back and forth, rotate and switch panes.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R2AC-505 ✅ PASS
Leaving the server mode no longer signs you out
Steps
  1. Sign in to Enterprise Server.
  2. Navigate Enterprise → entries, search, settings → Enterprise, then back.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R3AC-506 / AC-507 ✅ PASS
WebDAV errors now name the HTTP status
Steps
  1. Trigger a WebDAV error.
  2. Observe the error message.
  3. Check the support data for the recorded HTTP status.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R4AC-515 ✅ PASS
Samsung keyboard “https://” suggestion no longer leaves a space
Steps
  1. Open an entry editor with a URL field.
  2. Use the Samsung keyboard’s “https://” suggestion.
  3. Check the resulting value for a stray space.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R5AC-516 ✅ PASS
Chrome 131+ save dialog appears with the page change
Setup needed: A device with Chrome 131+.
Steps
  1. Log in on a test page in Chrome 131+ with a credential typed manually.
  2. Watch for the Password Depot save dialog as the page changes.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R6AC-518 / AC-519 ✅ PASS
Information entries in the server editor use Markdown
Steps
  1. Open an Information entry on the server in the editor.
  2. Check that there is a Markdown content editor and no separate comment field.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R7AC-520 ✅ PASS
Credit-card expiry 05/2026 stays 05/2026
Steps
  1. Create or edit a credit card entry with expiry 05/2026.
  2. Save, reopen, and check the stored value.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R8AC-521 ✅ PASS
PuTTY entries show “Key password”
Steps
  1. Create or open a PuTTY entry.
  2. Check the label of the key password field.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R9AC-487 ✅ PASS
New database starts with Windows default categories
Steps
  1. Create a new database.
  2. Open an entry editor and open the category picker.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R10AC-483 ✅ PASS
Start screen offers last server database when no local database exists
Steps
  1. Remove all local databases from the app (or use a fresh install).
  2. Open the app; observe the start screen.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R11AC-495 ✅ PASS
“New file replaces this database” notice disappears after unlocking
Steps
  1. Open a database over an existing one (staged replacement).
  2. Unlock successfully.
  3. Check that the notice is gone.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R12AC-458Sev-3 ✅ PASS
(One UI 7) Autofill test page follows the app language
Setup needed: Samsung device with One UI 7.
Steps
  1. Set a non-system app language.
  2. Open Settings → Autofill test.
  3. Check the page language and the app language after leaving.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R13AC-475Sev-3 ✅ PASS
Clipboard “Clear now” on Samsung — no app defect
Design: true
Steps
  1. Copy a password on a Samsung device.
  2. Pull down the full notification panel.
  3. Find the Password Depot notification and use “Clear now”.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)

Estimated time: 45–60 minutes. Run on every device you test.

A1 ✅ PASS
First Launch & Database Creation
Steps
  1. Fresh install (or update): open the app.
  2. Create a database with a name and a test master password.
  3. Confirm the empty entry list is shown.
  4. Relaunch the app.
  5. Enter the master password; confirm unlock.
  6. Enter a wrong master password.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A2 ✅ PASS
Entries of Several Types
Steps
  1. Create the following entries: password entry (with URL of a test account), credit card (PIN/CVV), identity entry, information entry, entry with a protected custom field.
  2. While typing secret fields (password, PIN, CVV, protected values), verify keyboard behavior.
  3. Open detail view for each entry.
  4. Edit each entry and re-save.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A3 ✅ PASS
Folders, Search, Trash
Steps
  1. Create two folders.
  2. Move entries between them.
  3. Search by title, username, and URL.
  4. Delete an entry (move to trash).
  5. Restore it from the recycle bin.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A4 ✅ PASS
Locking
Steps
  1. Background the app and return quickly (within the auto-lock time).
  2. Stay away past the auto-lock time (Settings → Security → Auto-lock).
  3. Force-close the app from Recents.
  4. Relaunch.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A5 ✅ PASS
Biometric Unlock + Invalidation
Steps
  1. Enable Settings → Security → Biometric unlock.
  2. Lock the database.
  3. Unlock using fingerprint/face.
  4. Go to Android system settings and enroll an additional fingerprint.
  5. Return to the app.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A6 ✅ PASS
Clipboard
Steps
  1. Copy a password from the detail view.
  2. Check if a countdown notification appears (Android 13+: grant notification permission if asked).
  3. Paste the password in another app — confirm it works.
  4. Wait 30 seconds; attempt to paste again.
  5. Try the “Clear now” button in the notification.
  6. Check the keyboard’s own clipboard history (Samsung/Gboard/SwiftKey).
Expected
Result
Status: ✅ PASS
Comments:
— none —
A7 ✅ PASS
Autofill in Your Daily Browser
Note: ⚠️ Chrome 131+ extra step required: Chrome → Settings → Autofill services → “Autofill using another service” → restart Chrome. Older Chrome reaches Password Depot only in an unreliable compatibility mode — please update Chrome.
Steps
  1. Enable Settings → Autofill service (follow system dialogs).
  2. Open Settings → Autofill test; confirm the suggestion appears on the built-in test form.
  3. Navigate to a test account login page in your browser.
  4. Verify autofill suggestion appears (inline chip or system sheet).
  5. Fill with Password Depot; confirm fields are filled correctly.
  6. Log in with a new credential typed manually; confirm save/update prompt appears.
  7. Negative check: navigate to a different or look-alike domain; confirm the entry is NOT offered under “Matching this site”.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A8 ✅ PASS
Autofill in One App
Steps
  1. Open any app with a login screen (use a test account).
  2. Trigger autofill.
  3. Test an app using Android Credential Manager (e.g. Facebook) if available.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A9 ✅ PASS
Appearance, Language, Rotation, Tablet
Steps
  1. Switch appearance: dark → light → system mode.
  2. Switch app language DE ↔ EN (Settings → App language on Android 13+).
  3. Rotate the device while unlocked; confirm session and selection survive.
  4. (Tablet/foldable only) Verify the two-pane list+detail layout.
  5. Note any clipped, untranslated, or oddly-worded text.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A10 ✅ PASS
Stability & Error Visibility
What to test: What to watch for throughout testing: any crash or ANR (app not responding); any freeze that requires a force-close; any error that is swallowed silently (action appears to work but data is wrong).
Steps
  1. If any of the above occur, open Support data immediately (lock → “Support data…” on unlock screen).
  2. Copy the version line and any listed events.
  3. File a Jira Bug with Sev-0 and attach the support data.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 3 — Focus Blocks C1–C11

Complete the blocks assigned to you, or any you have the setup for.

C1 ❌ FAIL
TOTP
Setup needed: A test account with 2FA / TOTP setup, and a reference authenticator app.
Steps
  1. Add a TOTP secret to a test entry using the entry editor.
  2. Use “Scan QR code” (camera or photo) to add the TOTP secret — test the QR scanner.
  3. Compare the 6-digit code with a reference authenticator for at least 3 consecutive periods.
  4. With autofill: open the 2FA field on a login page; confirm the code is offered only into the one-time-code field.
  5. Confirm the code is never offered into user/password fields.
Expected
Result
Status: ❌ FAIL
Tested device: Galaxy S22, Android 15
Comments:
https://internal.tracker.password-depot.de/browse/AC-537
C2 ✅ PASS
Passkeys (Android 14+)
Setup needed: Android 14+, device screen lock enabled. Test site: https://webauthn.io
Steps
  1. Settings → Passkey provider → select Password Depot. Verify the row shows “Enabled”.
  2. On webauthn.io: register a new passkey (should land in the Password Depot database).
  3. Sign in with the passkey using the same database.
  4. Move the passkey entry to the trash.
  5. Attempt sign-in again → expect “No matching passkey in the database”.
  6. Restore the passkey entry.
  7. Attempt sign-in again → confirm it works.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C3 ✅ PASS
WebDAV Sync
Setup needed: A real Nextcloud and/or Apache WebDAV server over HTTPS.
Steps
  1. Link the WebDAV server (Settings → Storage location & sync).
  2. Perform the initial database upload.
  3. Edit an entry on Android; sync; verify on Windows.
  4. Edit the same entry on both Android and Windows simultaneously.
  5. Sync from Android.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C4 ✅ PASS
Windows Interop
Setup needed: Windows Password Depot 19 and the same database accessible on both (file copy or WebDAV).
Steps
  1. Open the same .pswe file alternately in Windows PD 19 and Android.
  2. Verify that the following survive both directions (Android→Windows, Windows→Android): entries with umlauts/emoji in titles, folders and sub-folders, attachments, TAN lists (kept in file even though Android does not display them), entry history, custom icons, second-password (“four eyes”) entry.
  3. Specifically: set an expiry date on Android; open in Windows; confirm the date is preserved.
  4. Edit the same entry on both sides; sync; confirm a conflict copy appears rather than a silent overwrite.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C5 ✅ PASS
Attachments
Steps
  1. Attach a photo (a few MB) to an entry; reopen and export it; verify the file is intact.
  2. Attach a PDF (a few MB) to an entry; reopen and export it; verify the file is intact.
  3. Attempt to attach a file over 25 MB.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C6 ✅ PASS
Multi-Database & Master Password Change
What to test: Clarification: the app’s copy of every database lives in the app’s private storage, invisible to file managers by design. “The file must survive” refers to a database at a storage location (a file opened via “Open database file…”, WebDAV or cloud); a database created “on this device” has no external file — removing it deletes the only copy, and the app says so and offers “Export a copy first”.
Steps
  1. Create a second database; switch between both databases.
  2. Export a copy of the second database (Settings → Databases & sync → “Export a copy…”, save to Downloads).
  3. Open that file via “Open database file…” (it appears as “Connected to a storage location”).
  4. Remove THAT entry from the app — the file in Downloads must still exist — and open it again.
  5. A database created “on this device”: removing it deletes the only copy; the app must say so and offer “Export a copy first”.
  6. Note: after “remove from app” the backup copies the app kept for that database are gone too — use a database you do not need for C7.
  7. Change the master password of a test database.
  8. Attempt to unlock with the old password.
  9. Check biometric unlock status.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C7 ✅ PASS
Backup & Restore
Steps
  1. Navigate to Databases & sync → Backup copies; create a backup of a test database.
  2. Make a few changes to the database.
  3. Restore an earlier backup copy.
  4. Enter a wrong password during restore; check for throttle (3 s / 10 s delay) and message.
  5. Enter the correct password; confirm restore.
  6. Verify the restored state is complete; confirm the previous state was saved as a new backup copy first; confirm the chosen copy is still listed.
  7. (If database is linked to a storage source) Confirm a notice says the next sync will merge instead of replace.
  8. Attempt to restore a deliberately corrupted backup file.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C8 🚫 BLOCKED
Enterprise Thin Client
Setup needed: Office test server (Enterprise Server 20).
Steps
  1. Open the app → “Enterprise server…” on the start screen.
  2. Enter the server address and port; log in.
  3. On first connect: verify the TLS fingerprint confirmation dialog appears. Compare the SHA-256 with the server certificate (Windows: Home → PD Enterprise Server → “View server certificate”).
  4. Confirm server and port are remembered after the first successful login.
  5. Browse and search entries on the server.
  6. Edit an entry and save.
  7. Test sign-in with Windows domain credentials (DOMAIN\user or user@company.com) if AD is available.
Expected
Result
Status: 🚫 BLOCKED
Environment / blocker info: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments:
Enterprise Server v20 is not ready for testing.
C9 🚫 BLOCKED
Enterprise Offline Copy
Setup needed: Enterprise Server 20, TCP port 25020, a database with the offline right granted.
Steps
  1. Sign in to the server; tap “Save offline copy…” on the database list.
  2. Enter the server password (2FA accounts get a code field in step 2).
  3. Tap “Load databases” — confirm the TLS fingerprint once.
  4. Pick a database; confirm the copy is saved.
  5. Sign out; tap “Open offline copy” on the login screen; open with the server password.
  6. Verify the status line reads “Enterprise Server · offline copy”.
  7. Create/edit an entry offline; note the waiting-changes counter in the status line.
  8. Settings → Sync… → “Send changes to the server”: certificate question appears inside this screen; enter fingerprint; confirm all changes sent; “Load fresh copy” offered.
  9. Check: entry the server marks as non-editable → no edit action shown.
  10. Check: without export/save-as rights → Export and “Save as” are absent.
  11. Check: “Usable until” date matches the server’s offline period.
  12. Check: offline copy cannot be linked to cloud/WebDAV storage.
  13. Enter a wrong server password for an existing copy; confirm the error names the password (not “changes waiting”).
Expected
Result
Status: 🚫 BLOCKED
Environment / blocker info: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments:
Enterprise Server V20 is not ready for testing.
C10 ❌ FAIL
Enterprise Single Sign-On (OpenID Connect / Entra ID)
Setup needed: Enterprise Server 20 with a configured OpenID Connect or Entra ID sign-in provider; the provider registration must contain the redirect oidc.acebit://password-depot.de/.
Steps
  1. Choose “Single sign-on (OpenID Connect / Entra ID)” in the Enterprise login; tap “Connect”.
  2. Complete sign-in in the browser; confirm the app returns to the database list.
  3. Sign out; use “Sign in with a different account”; confirm the provider prompts for account selection.
  4. Start a sign-in and cancel it in the browser; confirm the app shows “The sign-in in the browser was cancelled”.
  5. Sign in with an account the server does not know; expect “The Enterprise Server did not accept the sign-in…”.
  6. Rotate the device while the browser is open; confirm the sign-in continues.
  7. Press Home during sign-in and return via the browser.
  8. (If configured) Test the second factor after sign-in.
Expected
Result
Status: ❌ FAIL
Tested device: Galaxy S22, Android 15
Comments:
https://internal.tracker.password-depot.de/browse/AC-608
C11 🚫 BLOCKED
Hand-Over of Previous-App Offline Changes
Setup needed: Enterprise Server 20, TCP port 25020. Either a previous-app installation with unsent offline changes, or the prepared file from the dev team.
Steps
  1. Start with the previous Password Depot for Android app installed and an Enterprise database with unsent offline changes.
  2. Update to this build; open “Import from previous app”; take the database over.
  3. Verify the report names the number of unsent changes and says they can be sent from the database.
  4. “Unlock now”: confirm the note at the top shows the same number.
  5. Tap “Send to the server…”: port 25020 and database name pre-filled; enter server, account, password.
  6. On first contact: certificate fingerprint question appears inside the dialog — enter it.
  7. Confirm the note disappears and the changes are on the server (verify in the Windows client).
  8. Test with a rejected change (e.g. no delete permission): note stays and names the reason; a later send tries only remaining open changes.
  9. Confirm the database never silently loses the note.
Expected
Result
Status: 🚫 BLOCKED
Environment / blocker info: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments:
Enterprise Server v20 is not ready for testing.

5 · Device Matrix Contribution

DimensionVariantCoveredNotes
Keyboard Gboard ✅
Keyboard Samsung Keyboard ✅
Keyboard SwiftKey ✅
Browser Chrome ✅
Browser Edge ✅
Browser Firefox ✅
Browser Samsung Internet ❌ https://internal.tracker.password-depot.de/browse/AC-494
Autofill style Android 11+ inline chips (note which you saw) —
Autofill style Android ≤13 dropdown —
Clipboard Samsung clipboard behavior ✅
Clipboard Pixel clipboard behavior ✅
Clipboard Xiaomi clipboard behavior ✅
Biometrics Fingerprint ✅
Biometrics Face unlock ✅
Biometrics Both enrolled ✅
OEM quirks Xiaomi/HyperOS battery saver — auto-lock reliable? ✅
OEM quirks Samsung battery saver — session killed mid-edit? ✅
Form factor Phone ✅
Form factor Tablet (≥ 600 dp) ✅
Form factor Foldable ✅
Storage FTPS / FTPES (new in beta21) —
Storage HiDrive (new in beta21) —

6 · Reporting Reference

Jira ProjectAndroid Client (AC)
Issue Type (bugs)Bug
Issue Type (coverage)Task
Affects Version20.0.0
Build line20.0.0-beta21 (1951)
Severity 0crash · data loss · lock-out
Severity 1feature wrong or unusable
Severity 2wrong, has a workaround
Severity 3visual / text
Deadlinewithin 10 working days
Bug summary format<area>: <short title>
Coverage summary formatBeta coverage: <device>

Support data: lock the app → tap “Support data…” on the unlock screen. Strictly local, secret-free. Copy version line + events into the issue.