Password Depot for Android — QA Test Report
Build 20.0.0-beta21 (1951) · Round 17 · Merged with 20.0.0-beta17 (1947) / Round 16 · Generated 9/22/2026, 4:11:45 PM
1 · Environment
| Device / Android | Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11 |
|---|
| Keyboard | Samsung Keyboard 5.9.12, Microsoft SwiftKey, Gboard |
|---|
| Browser(s) | Chrome 152, Edge 152, Firefox 155 |
|---|
| Build line | 20.0.0-beta21 (1951) |
|---|
| Tester | Sheva Ma |
|---|
| Date started | 2026-Sep-21 |
|---|
2 · Summary
| Block | Total | ✅ Pass | ❌ Fail | 🚫 Blocked | ⏭️ Skip | 🔄 In Progress | ⬜ Pending |
| Part 0 — Round 17 Re-Test: Beta17 Bug Fixes |
11 | 8 | 2 |
1 | 0 |
0 | 0 |
| Part 0b — Round 17 Audit Fix Wave (visible items) |
12 | 9 | 2 |
1 | 0 |
0 | 0 |
| Part 0c — Round 16 Re-Test: Beta15 Bug Fixes (historical) |
11 | 10 | 1 |
0 | 0 |
0 | 0 |
| Part 0d — Round 16 New Features (beta17) (historical) |
10 | 8 | 2 |
0 | 0 |
0 | 0 |
| Part 0e — Round 14 Re-Test: Beta13 Bug Fixes (historical) |
13 | 13 | 0 |
0 | 0 |
0 | 0 |
| Part 1 — Core Pass: A1–A10 (Every Tester, Every Device) |
10 | 10 | 0 |
0 | 0 |
0 | 0 |
| Part 3 — Focus Blocks C1–C11 |
11 | 7 | 3 |
1 | 0 |
0 | 0 |
| Total | 78 | 65 | 10 |
3 | 0 |
0 | 0 |
| Items tested / total | 75 / 78 |
| Pass rate (of decided items) | 87% |
| Failures (checklist items) | 10 |
| Blocked items | 3 |
| New bugs discovered (manual entry) | 7 |
| Skipped | 0 |
3 · Failures (10)
R17-4
AC-480
Entries protected with a second password are recognised in the autofill picker
Section: Part 0 — Round 17 Re-Test: Beta17 Bug Fixes
Tested device: Galaxy S22, Android 15
Comments / Jira key: I’m able to see the entry list now, but once I click the entry, nothing happens, please check below screen recording.
R17-9
AC-543
New storage locations: FTPS/FTPES and HiDrive
Section: Part 0 — Round 17 Re-Test: Beta17 Bug Fixes
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-609
AUD-2
AC-547 / AC-548
Second-password entries keep custom fields when edited
Section: Part 0b — Round 17 Audit Fix Wave (visible items)
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-611
AUD-6
AC-595 / AC-596 / AC-560
Server passkeys stop after sign-out; bad challenge rejected properly
Section: Part 0b — Round 17 Audit Fix Wave (visible items)
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-615
S8
AC-493 / AC-494
Pinned browser without a web address is no longer treated as a native app
Section: Part 0c — Round 16 Re-Test: Beta15 Bug Fixes (historical)
Tested device: Android 14 on Galaxy S24 Ultra
Comments / Jira key: AC-494 still reproducible.
T1
AC-508
Entries with a second password can be edited again
Section: Part 0d — Round 16 New Features (beta17) (historical)
Tested device: Galaxy S22, Android 15
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-611
T8
AC-512
Server editor: TOTP set / change / remove
Section: Part 0d — Round 16 New Features (beta17) (historical)
Tested device: Galaxy S22, Android 15
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-614
C1
TOTP
Section: Part 3 — Focus Blocks C1–C11
Tested device: Galaxy S22, Android 15
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-537
C9
Enterprise Offline Copy
Section: Part 3 — Focus Blocks C1–C11
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-617
C10
Enterprise Single Sign-On (OpenID Connect / Entra ID)
Section: Part 3 — Focus Blocks C1–C11
Tested device: Galaxy S22, Android 15
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-608
3a · New Bugs Discovered (Manual Entry) (7)
Bugs entered manually during this round; not part of the fixed checklist. One finding per entry — copy the Jira key into the tracker.
NEW #1
AC-608
Sev-2
SSO / OpenID Connect login fails on Android client when 2FA is enabled on Enterprise Server
Tested device: Galaxy S22, Android 15
Description / Steps to reproduce:
Environment:
Client: Android Client (v20.0.0 Beta 21)
Android 15, Samsung Galaxy S22.
Connection: Enterprise Server (Port: 8714, Sign-in method: Single sign-on (OpenID Connect / Entra ID))
Steps to Reproduce:
1. Enable Two-Factor Authentication (2FA) on the Password Depot Enterprise Server.
2. Open Android client and navigate to "Connect to Enterprise Server".
3. Enter Server address and Port (e.g., 8714).
4. Select Sign-in method: "Single sign-on (OpenID Connect)".
5. Tap "Connect" and complete the company account (Entra ID / OpenID Connect) sign-in in browser.
Expected Result:
Login succeeds or prompts for required 2FA / TOTP second-factor verification as expected.
Actual Result:
Sign-in fails with error message:
"The Enterprise Server did not accept the sign-in. Your account may not be linked to this sign-in service yet."
NEW #2
AC-609
Sev-2
WebDAV/HiDrive DB: URL contains "#$" causes UI validation error; error message incorrect even when URL ends with .pswe
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Description / Steps to reproduce:
Problem Summary:
When opening a WebDAV (Strato HiDrive) database, if the URL contains the characters #$, the UI immediately shows an error/validation state. The error message is misleading/incorrect: it complains that the address must end with a file name (e.g. database.pswe) even though the provided URL already ends with .pswe.
NEW #3
AC-613
Sev-2
Server DB: Category field does not display dropdown / selection menu in entry editor
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Description / Steps to reproduce:
Problem Summary:
In the Android client, when creating or editing an entry within a Server Database (Enterprise Server DB), the Category field does not provide a dropdown menu or selection list to pick from available server categories.
NEW #4
AC-614
Sev-2
Server DB: TOTP field does not support QR code scanning in entry editor
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Description / Steps to reproduce:
Environment / Preconditions
* Client Version: Password Depot for Android 20.0.0 Beta21
* Database Type: Enterprise Server Database (.pswe on PD Enterprise Server v20)
Steps to Reproduce
1. Open and log in to an Enterprise Server Database.
2. Tap + to create a new entry (or open an existing entry to edit).
3. Scroll down to the TOTP (Time-based One-Time Password) section / field.
4. Check for the option / button to scan a TOTP QR code (or tap the QR scan icon).
Observed Result
* In Server DB entries, the QR code scan icon/button is missing, disabled, or tapping it does not invoke the camera scanner.
* Users can only manually type/paste the raw TOTP secret key, which is error-prone and degrades user experience compared to Local DB entries.
Expected Result
* Just like in Local DB entries, the TOTP field in Server DB entries should provide a QR code scanner button .
* Tapping the button should launch the camera scanner, parse the otpauth://totp/... URI from the QR code, and automatically populate the TOTP secret, algorithm, digits, and interval.
NEW #5
AC-615
Sev-2
OIDC SSO: passkey unlock launches PD master-password prompt after sign-out (blocks WebAuthn auth)
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Description / Steps to reproduce:
Problem Summary:
After signing out from an OIDC SSO database, users cannot continue WebAuthn authentication.
The passkey/password unlock flow ends in a Password Depot master-password prompt, which blocks access because OIDC/SSO-authenticated databases do not have a master password.
NEW #6
AC-617
Sev-2
Sync: "Sign in with OIDC" button has no response on "Load fresh copy from the server" dialog
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Description / Steps to reproduce:
Problem Summary:
When attempting to sync/refresh an offline Enterprise Server database via "Load fresh copy from the server", clicking the "Sign in with OIDC" button in the sign-in modal does nothing.
NEW #7
AC-611
Sev-2
Second password: Saved field contents lost on next save due to unprotect/reprotect projection discarding undecrypted custom fields and U+FFFD characters
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Description / Steps to reproduce:
Problem Summary:
When editing an entry protected by a second password and changing the second password via the "Change second password" button, saving the entry results in a decryption error upon opening/saving (The password could not be decrypted with this second password). Additionally, obsolete read-only info banners and text wrapping UI defects are present.
3b · Blocked Items (3)
Items that could not be executed at all — missing test environment, missing server build, no hardware, etc. Each entry names the blocker.
R17-8
AC-544
Settings taken over from the old app (needs 19.x migration)
Section: Part 0 — Round 17 Re-Test: Beta17 Bug Fixes
Environment / blocker info: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Blocker / Comments: Update not working, as the signatures is different.
adb: failed to install /Users/sheva/Downloads/Password Depot/Password Depot - Android Beta/beta 21/PasswordDepot-Android-20.0.0-beta21.apk: Failure [INSTALL_FAILED_UPDATE_INCOMPATIBLE: Existing package de.acebit.passworddepot signatures do not match newer version; ignoring!]
AUD-12
AC-580 / AC-564 / AC-565
Takeover wording unified; FAQ corrected
Section: Part 0b — Round 17 Audit Fix Wave (visible items)
Environment / blocker info: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Blocker / Comments: As upgrade not working based on the signatures issue, hence cannot verify this feature for now.
C11
Hand-Over of Previous-App Offline Changes
Section: Part 3 — Focus Blocks C1–C11
Environment / blocker info: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Blocker / Comments: As upgrade not working based on the signatures issue, hence cannot verify this for now.
4 · Detailed Results
Part 0 — Round 17 Re-Test: Beta17 Bug Fixes
These bugs were reported in Round 16 and claimed fixed in beta21. Re-test every one on build 1951.
R17-1AC-539Sev-1 ✅ PASS
Firefox shows “Fill in with Password Depot” again
What to test: Firefox stopped showing the autofill suggestion in Round 16. The fix restores “Fill in with Password Depot”.
Steps
- Enable Settings → Autofill service.
- Open a login page in Firefox with a saved matching entry.
- Trigger autofill / tap in the login field.
Expected
- The suggestion “Fill in with Password Depot” appears.
- The entry fills correctly when selected.
Result
Status: ✅ PASS
Comments:
R17-2AC-538Sev-2 ✅ PASS
Server DB: manually loaded entries stay listed while search box is empty
What to test: With an Enterprise Server database, entries loaded manually stayed listed when the search box was empty. Partial fix: the full Edge case stays open.
Known issue / note: Partial fix — the full Edge case stays open. Please report separately if the Edge variant still fails.
Steps
- Open an Enterprise Server database in the app.
- Trigger autofill; load entries manually.
- Clear the search box and observe whether the entries remain listed.
Expected
- Manually loaded entries stay listed while the search box is empty.
- No entries disappear until a new search is run.
Result
Status: ✅ PASS
Comments:
R17-3AC-540Sev-3 ✅ PASS
Permanent setup banner on Android 14 no longer sticks
What to test: The permanent autofill setup banner on Android 14 stayed visible. Partial fix.
Known issue / note: Partial fix.
Steps
- Set up autofill on Android 14.
- Dismiss the setup banner.
- Navigate back to the home screen.
Expected
- The setup banner does not stick after dismissal.
- It does not reappear without a state change.
Result
Status: ✅ PASS
Tested device: Galaxy S22, Android 15
Comments:
R17-4AC-480Sev-1 ❌ FAIL
Entries protected with a second password are recognised in the autofill picker
What to test: The autofill picker now explains why the password or one-time code is not handed out, and you can pick another entry.
Steps
- Create an entry with a second password.
- Trigger autofill on a matching site.
- Tap the protected entry in the picker.
Expected
- The picker explains why the password/one-time code is not handed out.
- The window stays open so another entry can be picked.
Result
Status: ❌ FAIL
Tested device: Galaxy S22, Android 15
Comments:
R17-5AC-541Sev-1 ✅ PASS
Clipboard countdown no longer loops; clipboard is really cleared
Setup needed: Galaxy S26 Ultra / Android 16 (Sheva please re-test).
What to test: The countdown looped from 30 s to 1 s forever, and the clipboard was not actually cleared.
Steps
- Copy a password from the detail view.
- Observe the countdown notification.
- Wait until the countdown reaches zero.
- Attempt to paste the password in another app.
Expected
- Countdown decreases normally and reaches zero.
- Clipboard is truly cleared; the value cannot be pasted.
- No loop back to 1 s.
Result
Status: ✅ PASS
Comments:
R17-6AC-517Sev-1 ✅ PASS
Passkeys on a server database stay in that database
What to test: Creating a passkey while a server database is active now stores it in that database — before, it silently went into the previously opened local file.
Steps
- Open a server database in the app.
- Create a passkey on a website (webauthn.io or another test site).
- Check in which database the passkey landed.
- Switch to the local database and check there too.
Expected
- The passkey is stored in the active server database.
- It does NOT silently go to a previously opened local file.
Result
Status: ✅ PASS
Comments:
R17-7AC-542Sev-2 ✅ PASS
Entry icons for types without a URL field
What to test: Entry types without a URL field (nine types) can load an icon from a web address typed in the icon picker; the field is prefilled with the entry’s address where one exists.
Steps
- Open an entry type without a URL field (e.g. Identity, Information, PuTTY).
- Open the icon picker.
- Type a web address; load the icon.
Expected
- The icon is fetched from the typed address.
- The field is prefilled with the entry’s address where one exists.
Result
Status: ✅ PASS
Comments:
R17-8AC-544Sev-1 🚫 BLOCKED
Settings taken over from the old app (needs 19.x migration)
Setup needed: A real 19.x installation to migrate from.
What to test: The takeover now brings the lock timeout, appearance, and master-password policy; biometric unlock is offered per database after the first unlock instead of being copied. Olha’s ten steps are in AC-602.
Steps
- Install a 19.x build with custom lock timeout, appearance, and master-password policy.
- Update to this build and run “Import from previous app”.
- Check the takeover report.
- Verify lock timeout, appearance, master-password policy.
- Verify biometric unlock is offered per database after first unlock.
Expected
- Lock timeout is carried over (30/60/120/300 s; “never lock” → 15 minutes; device policy wins).
- Appearance is carried over.
- Master-password policy is carried over.
- Biometric unlock is offered per database, not copied.
- Takeover report lists what was taken over and what was skipped.
Result
Status: 🚫 BLOCKED
Environment / blocker info: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments:
R17-9AC-543Sev-1 ❌ FAIL
New storage locations: FTPS/FTPES and HiDrive
Setup needed: Your own FTPS server, or ask for the test server.
What to test: An FTPS or FTPES server can hold a database like WebDAV does, with a certificate-fingerprint question on first contact. HiDrive is its own entry in the provider list. Plain FTP is NOT offered (as in Windows 20).
Steps
- Open “Open from cloud…” or “Storage location & sync”.
- Add an FTPS/FTPES server.
- On first contact, compare the certificate fingerprint question.
- Verify the fingerprint matches the server’s.
- Add HiDrive as a provider; verify the row says “HiDrive”.
- Verify OneDrive row says “personal or business account (OneDrive for Business)”.
- Verify no plain FTP option exists.
Expected
- Certificate fingerprint question appears once on first contact.
- Fingerprint matches the server’s.
- HiDrive is its own provider entry.
- OneDrive row reads “personal or business account”.
- No plain FTP option.
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments:
R17-10AC-458Sev-3 ✅ PASS
Language: Early Android 15 no longer keeps Chinese texts
Setup needed: Galaxy S22 / One UI 7 confirmation wanted.
What to test: Early Android 15 could keep Chinese texts after switching the system language back to English; English texts are now explicit resources.
Steps
- Set system language to Chinese.
- Set app language to English.
- Switch system language back to English.
- Observe app texts.
Expected
- App texts stay in English.
- No Chinese text remains after the switch.
Result
Status: ✅ PASS
Comments:
R17-11AC-545Sev-1 ✅ PASS
Invisible: Intune app protection SDK (dormant)
What to test: The Microsoft Intune SDK is back in the app as in 19.x. It is dormant without a company setup and there is no menu entry yet; nothing should look or behave differently.
Steps
- Note start-up time and behaviour on first launch.
- Use autofill, passkeys and normal flows.
- Watch for any unexpected network or sign-in prompt.
Expected
- No visible change to start-up time or behaviour.
- No unexpected network or sign-in prompt.
- Any change (start-up, autofill, prompts) is a finding.
Result
Status: ✅ PASS
Comments:
Part 0b — Round 17 Audit Fix Wave (visible items)
Two independent code reviews on 19 Sep produced 56 findings; all but one are fixed (AC-546 to AC-601, AC-576 was no error). These are the ones you can see. Each ticket names its own steps in Jira — sample them.
AUD-1AC-546 / AC-585 / AC-597 ✅ PASS
Documents keep the right encryption mode
What to test: Documents keep the right encryption mode after a master-password change or a mode switch.
Steps
- Create a document entry.
- Change the master password.
- Switch the encryption mode (if applicable).
- Reopen the document and verify the file is intact.
Expected
- Document stays readable and intact after password change or mode switch.
- No encryption mode mismatch.
Result
Status: ✅ PASS
Comments:
AUD-2AC-547 / AC-548 ❌ FAIL
Second-password entries keep custom fields when edited
What to test: Entries with a second password keep their custom fields when edited.
Steps
- Create an entry with a second password and a custom field.
- Unlock with the second password; edit a field; save.
- Reopen and verify the custom field is intact.
Expected
- Custom fields survive the edit.
- No data is lost.
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments:
AUD-3AC-549 / AC-556 / AC-557 / AC-591 ✅ PASS
SSO offline copies stay usable; require fresh provider sign-in
What to test: SSO offline copies keep their backups usable and open only after a fresh provider sign-in, never by biometrics alone.
Steps
- Save an offline copy while signed in with SSO.
- Sign out; attempt to open the offline copy.
- Observe the required sign-in.
- Check that backups of the copy are still usable.
Expected
- Offline copy opens only after a fresh provider sign-in.
- Never opens by biometrics alone.
- Backups remain usable.
Result
Status: ✅ PASS
Comments:
AUD-4AC-587 / AC-588 / AC-589 / AC-601 ✅ PASS
Switching database slot during sync no longer writes into the other database
What to test: Switching the database slot during a running sync, journal or offline operation no longer writes into the other database.
Steps
- Start a sync / journal / offline operation on database A.
- While it is running, switch to database B.
- Verify that no writes leaked into database B.
- Return to database A and confirm the operation completed correctly.
Expected
- No cross-database writes.
- The operation completes correctly on the original database.
Result
Status: ✅ PASS
Comments:
AUD-5AC-590 ✅ PASS
Foreign database at same cloud path does not break the slot
What to test: A foreign database at the same cloud path no longer breaks the slot.
Steps
- Place a non-Password-Depot file at the same cloud path.
- Open the slot in the app.
- Observe the error handling.
Expected
- Slot does not break; a clear error is shown.
- App remains usable.
Result
Status: ✅ PASS
Comments:
AUD-6AC-595 / AC-596 / AC-560 ❌ FAIL
Server passkeys stop after sign-out; bad challenge rejected properly
What to test: Server passkeys stop after sign-out and reject a bad challenge with a proper error. A protected server passkey no longer blocks unprotected matches.
Steps
- Create a passkey on a server database.
- Sign out from the server.
- Attempt a passkey sign-in — should fail with a proper error.
- Have a protected and an unprotected passkey for the same site; verify the unprotected one is still offered.
Expected
- Passkey sign-in stops after sign-out.
- Bad challenge is rejected with a proper error.
- Protected passkey does not block unprotected matches.
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments:
AUD-7AC-567 / AC-568 / AC-569 ✅ PASS
Rotating device during a system dialog keeps state
What to test: Rotating the device during a system dialog keeps category changes, the file-picker target and the document export.
Steps
- Open a system dialog (category change, file picker, document export).
- Rotate the device.
- Complete the dialog and verify the state was preserved.
Expected
- Category changes are preserved.
- File-picker target is preserved.
- Document export target is preserved.
Result
Status: ✅ PASS
Comments:
AUD-8AC-573 / AC-578 / AC-570 ✅ PASS
Server search shows waiting state; SSO user name in status; custom field shows new value
What to test: The server search shows a waiting state instead of stale results, the status line shows your user name after SSO, and a saved custom field shows its new value.
Steps
- Run a server search and observe the waiting state.
- Sign in with SSO and check the status line.
- Edit a custom field, save, reopen and verify the new value.
Expected
- Search shows waiting state, not stale results.
- Status line shows the SSO user name.
- Saved custom field shows its new value.
Result
Status: ✅ PASS
Comments:
AUD-9AC-562 / AC-563 / AC-559 ✅ PASS
Export blocked by policy says so; full device named; long passwords warned
What to test: An export blocked by policy says so, a full device is named as the cause, and long passwords are no longer silently cut to 512 characters — you get a notice.
Steps
- Attempt an export blocked by MDM policy.
- Attempt an export on a full device.
- Enter a very long password (>512 characters) and save.
Expected
- Export blocked by policy says so.
- Full device is named as the cause.
- Long password shows a notice, not silent truncation.
Result
Status: ✅ PASS
Comments:
AUD-10AC-586 / AC-582 / AC-581 ✅ PASS
Backups browsable; recycle bin reachable in large DBs; lists easier to navigate
What to test: Backups can be browsed and old entries viewed before restoring, the recycle bin is reachable in large databases, and very long lists are easier to navigate (fast-scroll handle deferred).
Steps
- Open a backup and browse entries before restoring.
- Open the recycle bin in a large database.
- Scroll a very long list and use the navigation aids.
Expected
- Backups are browsable before restore.
- Recycle bin is reachable in large databases.
- Long lists are easier to navigate.
Result
Status: ✅ PASS
Comments:
AUD-11AC-566 / AC-579 / AC-583 ✅ PASS
Cloud write unverified reported; external backup streams; server autofill asks one question
What to test: A cloud write that could not be verified is reported as exactly that instead of “rejected, HTTP 200”; the external backup copy streams instead of loading the whole file into memory; server autofill after a session end asks one plain question with two options.
Steps
- Trigger a cloud write that cannot be verified.
- Create an external backup copy of a large database.
- End a server session and trigger autofill.
Expected
- Unverified write is reported accurately.
- External backup streams without high memory use.
- Autofill asks one plain question with two options.
Result
Status: ✅ PASS
Comments:
AUD-12AC-580 / AC-564 / AC-565Sev-3 🚫 BLOCKED
Takeover wording unified; FAQ corrected
What to test: The takeover wording is unified and the FAQ corrected.
Steps
- Open the takeover screen and the FAQ.
- Check for consistent wording.
Expected
- Consistent wording across takeover screens.
- FAQ matches the current behaviour.
Result
Status: 🚫 BLOCKED
Environment / blocker info: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments:
Part 0c — Round 16 Re-Test: Beta15 Bug Fixes (historical)
These bugs were reported in Round 14 and claimed fixed in beta17. Kept for regression coverage — re-test if you have the setup or if the round-17 list touches the same area.
S1AC-523Sev-1 ✅ PASS
An expired Enterprise Server session really ends the session
What to test: After ten minutes without server traffic you are taken back to the sign-in screen instead of still being able to open and copy entries.
Steps
- Sign in to Enterprise Server.
- Wait ~10 minutes without server traffic (or trigger an expired-session state).
- Try to open or copy an entry.
- Open the editor, make a change, wait for expiry, then attempt to save.
Expected
- You are taken back to the sign-in screen.
- Open editor draft survives; save asks you to sign in again.
Result
Status: ✅ PASS
Comments:
S2AC-526Sev-1 ✅ PASS
Unlocking a local or cloud database makes autofill use it
What to test: Unlocking a local or cloud database now makes autofill use it instead of the last server database.
Steps
- First open an Enterprise Server database, then lock it.
- Unlock a local or cloud database.
- Trigger autofill in a browser.
Expected
- Autofill uses the currently unlocked local/cloud database.
- It does not fall back to the last server database.
Result
Status: ✅ PASS
Comments:
S3AC-527 ✅ PASS
Cloud account shows as connected right after sign-in
Steps
- Open Settings → Databases & sync → Cloud accounts.
- Sign in to a cloud provider.
- Return to Cloud accounts.
Expected
- The account appears as connected right away.
Result
Status: ✅ PASS
Comments:
S4AC-530 ✅ PASS
“File already exists” appears immediately when picking an existing database
Steps
- Open from cloud / Open database file… and pick a file that already exists in the app.
- Observe the timing of the “File already exists” message.
Expected
- The message appears immediately when the file is picked.
Result
Status: ✅ PASS
Comments:
S5AC-480 ✅ PASS
Server entry protected by a second password is marked in autofill
Steps
- Create a server entry with a second password.
- Trigger autofill on a matching site.
- Tap the marked entry.
Expected
- Entry is marked in the autofill list.
- Tap explains why it cannot be filled.
- Window stays open so another entry can be picked.
Result
Status: ✅ PASS
Comments:
S6AC-487 ✅ PASS
Category picker in the server editor offers the categories
Steps
- Open a server entry in the editor.
- Open the category picker.
Expected
- Categories are offered.
- The picker behaves like the local editor.
Result
Status: ✅ PASS
Comments:
S7AC-458Sev-3 ✅ PASS
App language wraps all 14 windows (incl. autofill and passkey dialogs)
Setup needed: Galaxy S22 with system language in Chinese.
Steps
- Set the app language to a non-system language.
- Open the autofill window and the passkey dialogs.
- Verify all text follows the app language.
Expected
- All 14 windows follow the app language.
- No window flips back to the system language.
Result
Status: ✅ PASS
Comments:
S8AC-493 / AC-494 ❌ FAIL
Pinned browser without a web address is no longer treated as a native app
Setup needed: Edge and Samsung Internet installed and pinned.
Steps
- Open Edge or Samsung Internet with no web address.
- Trigger autofill.
Expected
- Entries belonging to the browser package are not offered.
- Only domain-matched entries are offered.
Result
Status: ❌ FAIL
Tested device: Android 14 on Galaxy S24 Ultra
Comments:
S9AC-517 ✅ PASS
Passkeys of an open Enterprise Server database are offered before the local ones
Setup needed: Chrome 131 or newer.
Steps
- Open the Enterprise Server database in the app.
- Trigger a passkey sign-in in Chrome 131+ on a site matching both databases.
Expected
- Server database passkeys are offered first.
- Local passkeys follow.
Result
Status: ✅ PASS
Comments:
S10AC-522Sev-3 ✅ PASS
Server mode navigation rail: first item is “Home”, no search
Steps
- Switch to server mode on a tablet (or wide layout).
- Observe the navigation rail.
Expected
- First item is “Home”.
- No search in the rail.
Result
Status: ✅ PASS
Comments:
S11AC-524Sev-0 ✅ PASS
Home screen no longer reads autofill setup state without a safety net (Xiaomi crash)
Setup needed: Xiaomi device.
Steps
- Open the app on a Xiaomi device.
- Check for any crash on the home screen.
- If it crashes, attach the device log.
Expected
- No crash on the home screen.
Result
Status: ✅ PASS
Comments:
Part 0d — Round 16 New Features (beta17) (historical)
New in beta17. Kept for regression coverage.
T1AC-508Sev-0 ❌ FAIL
Entries with a second password can be edited again
What to test: Unlock a protected entry with its second password; it edits like any other entry. A new row Second password lets you set / change / remove it. The dialog says plainly that there is no recovery.
⭐ Big feature: ⭐ THE BIG ONE from Round 16 — the previous Android app 19.x could do this; 20.0.0 could not until beta17.
Steps
- Open an entry with a second password.
- Unlock it with its second password.
- Edit its user name and/or password.
- Save; verify values go back under the same second password without asking again.
- On an unprotected entry: set a second password (enter twice), then change it, then remove it.
- Open the same database in Password Depot for Windows and check the entry there.
Expected
- Protected entry is editable after unlocking with its second password.
- Save keeps the same second password without asking again.
- Set / change / remove second password works.
- Windows client reads the entry correctly — this is the check that matters most.
- The dialog warns: no recovery if forgotten.
Result
Status: ❌ FAIL
Tested device: Galaxy S22, Android 15
Comments:
T2AC-528 / AC-529Sev-1 ✅ PASS
Cloud accounts — account switch end to end
What to test: Cloud accounts list shows every connected provider with its account and a Sign out. Signing out disconnects and revokes the token; the next sign-in lets you pick a different account. A database stays with the cloud account it was linked to.
Steps
- Open Settings → Databases & sync → Cloud accounts.
- Sign out a connected provider.
- Sign in again; verify the provider lets you pick a different account.
- Open a database of account 1 while account 2 is connected.
- Reproduce with Dropbox, OneDrive, and Google Drive.
Expected
- Cloud accounts list shows provider + account + Sign out.
- Sign out disconnects the account and revokes the token.
- Next sign-in lets you pick a different account.
- Account mismatch is refused and names both accounts.
Result
Status: ✅ PASS
Comments:
T3AC-514 / AC-510 ✅ PASS
Entry editor — pinned Save header + Symbol row after URL rows
Steps
- Open a long form entry editor and scroll to the bottom.
- Verify the Save header stays pinned.
- For a type with URLs: verify the Symbol row sits after the URL rows.
- For a type without URLs: verify the Symbol row is where it was.
Expected
- Save is reachable from the bottom of a long form.
- Symbol row sits after URL rows where URLs exist.
- Entry types without URLs keep the previous symbol row position.
Result
Status: ✅ PASS
Comments:
T4AC-534Sev-0 ✅ PASS
Key files — unlock always asks explicitly (no silent copies)
Setup needed: A database protected by a key file.
What to test: A normal unlock now always asks for the key file explicitly; the app no longer keeps or creates silent copies of it. Exporting a key file is read back after writing and obeys the export policy.
Steps
- Unlock a key-file-protected database.
- Verify the app asks for the key file explicitly.
- Check Settings for any stored key-file copy; revoke if present.
- Export a key file; verify the file is read back and the export policy is obeyed.
- Test unlock, backup and restore.
Expected
- Unlock always asks for the key file explicitly.
- No silent copies are created or kept.
- Any earlier stored copy is recoverable and revocable in the settings.
- Export is read back and obeys policy.
- Unlock, backup and restore all work.
Result
Status: ✅ PASS
Comments:
T5AC-532Sev-3 ✅ PASS
Unlock error messages with a key file
Steps
- Attempt unlock with a wrong key file only.
- Attempt unlock with a wrong password plus a key file.
- Attempt unlock with a wrong password only.
- Repeat the same in the autofill window and the passkey dialog.
Expected
- Wrong key file alone → “The key file is incorrect.”
- Wrong password + file → “The master password and/or key file are incorrect.”
- Password-only text unchanged.
- Same texts appear in autofill and passkey windows.
Result
Status: ✅ PASS
Comments:
T6AC-477 ✅ PASS
Autofill can optionally keep one unlock for a short while (OFF by default)
Design: true
Steps
- Turn the option on in the settings.
- Authenticate once; fill an entry.
- Fill another entry within the window; verify no re-auth prompt.
- Wait past the window; verify re-auth is required.
- Lock the device or app; verify the window is revoked immediately.
- Turn the option back off (default).
Expected
- Option is off by default.
- Window starts at first authentication, not extended by further fills.
- Still pick every entry yourself.
- Lock / database change / timeout / process end revoke immediately.
Result
Status: ✅ PASS
Comments:
T7AC-468Sev-1 ✅ PASS
Entry layouts now follow the Windows client
Setup needed: Windows Password Depot 20 with the same database.
Steps
- Open a local entry and a server entry of the same type side by side with Windows.
- Compare field order and grouping per type.
- Open a Banking entry; verify expiry is MM/YYYY.
- Add a field the app does not know on Windows; save on Android; verify it is preserved.
Expected
- Field order and grouping match Windows per type.
- Banking expiry is MM/YYYY.
- Unknown fields are kept untouched.
Result
Status: ✅ PASS
Comments:
T8AC-512Sev-1 ❌ FAIL
Server editor: TOTP set / change / remove
Setup needed: Enterprise Server with ES-990.
Steps
- Open a server entry in the editor.
- Set a TOTP secret; save.
- Change the TOTP secret; save.
- Remove the TOTP secret; save.
- Open an unsaved server entry; verify TOTP setup only appears after the first save.
Expected
- TOTP secret can be set, changed and removed on the server.
- Unsaved entry shows TOTP setup only after the first save.
Result
Status: ❌ FAIL
Tested device: Galaxy S22, Android 15
Comments:
T9AC-535 / AC-533Sev-2 ✅ PASS
Cloud accounts — Dropbox real name + account mismatch notice
Steps
- Sign in to Dropbox; verify the real account name is shown.
- Trigger an account mismatch; verify the notice can be dismissed.
- Trigger an unlock error; switch database slots or go to settings; verify the error disappears.
Expected
- Dropbox shows the real account name.
- Account mismatch is a dismissible notice.
- Unlock errors do not stick after switching slots or visiting settings.
Result
Status: ✅ PASS
Comments:
T10AC-497Sev-2 ✅ PASS
Enterprise sign-in — precise e-mail messages keep wording under SSO
Setup needed: Enterprise Server with an SSO-configured sign-in provider.
Steps
- Attempt sign-in with an unknown e-mail address under SSO.
- Attempt sign-in with a blocked e-mail address under SSO.
Expected
- Precise messages keep their wording under SSO.
- No generic rejection replaces them.
Result
Status: ✅ PASS
Comments:
Part 0e — Round 14 Re-Test: Beta13 Bug Fixes (historical)
These bugs were reported in Round 13 and claimed fixed in beta15. Kept for regression coverage.
R1AC-496Sev-0 ✅ PASS
Crash “Placement happened before lookahead” in list/detail layout
Steps
- Repeat both step sequences from the original report on a Galaxy S22 with a cloud database.
- Open the list, open a detail, navigate back and forth, rotate and switch panes.
Expected
- No crash “Placement happened before lookahead”.
- List/detail layout behaves correctly on phones and tablets.
Result
Status: ✅ PASS
Comments:
R2AC-505 ✅ PASS
Leaving the server mode no longer signs you out
Steps
- Sign in to Enterprise Server.
- Navigate Enterprise → entries, search, settings → Enterprise, then back.
Expected
- Leaving the server mode does not sign you out.
Result
Status: ✅ PASS
Comments:
R3AC-506 / AC-507 ✅ PASS
WebDAV errors now name the HTTP status
Steps
- Trigger a WebDAV error.
- Observe the error message.
- Check the support data for the recorded HTTP status.
Expected
- Message names the HTTP status, e.g. “The storage location answered with an error (HTTP 413) …”.
Result
Status: ✅ PASS
Comments:
R4AC-515 ✅ PASS
Samsung keyboard “https://” suggestion no longer leaves a space
Steps
- Open an entry editor with a URL field.
- Use the Samsung keyboard’s “https://” suggestion.
- Check the resulting value for a stray space.
Expected
- No space is inserted after “https://”.
Result
Status: ✅ PASS
Comments:
R5AC-516 ✅ PASS
Chrome 131+ save dialog appears with the page change
Setup needed: A device with Chrome 131+.
Steps
- Log in on a test page in Chrome 131+ with a credential typed manually.
- Watch for the Password Depot save dialog as the page changes.
Expected
- Save dialog appears reliably after the login.
Result
Status: ✅ PASS
Comments:
R6AC-518 / AC-519 ✅ PASS
Information entries in the server editor use Markdown
Steps
- Open an Information entry on the server in the editor.
- Check that there is a Markdown content editor and no separate comment field.
Expected
- Markdown content editor, no separate comment field.
- Detail view renders Markdown.
Result
Status: ✅ PASS
Comments:
R7AC-520 ✅ PASS
Credit-card expiry 05/2026 stays 05/2026
Steps
- Create or edit a credit card entry with expiry 05/2026.
- Save, reopen, and check the stored value.
Expected
- Value is stored and displayed as 05/2026.
Result
Status: ✅ PASS
Comments:
R8AC-521 ✅ PASS
PuTTY entries show “Key password”
Steps
- Create or open a PuTTY entry.
- Check the label of the key password field.
Expected
- Label reads “Key password”.
Result
Status: ✅ PASS
Comments:
R9AC-487 ✅ PASS
New database starts with Windows default categories
Steps
- Create a new database.
- Open an entry editor and open the category picker.
Expected
- Default categories are present in the app language.
- Category picker is never empty.
Result
Status: ✅ PASS
Comments:
R10AC-483 ✅ PASS
Start screen offers last server database when no local database exists
Steps
- Remove all local databases from the app (or use a fresh install).
- Open the app; observe the start screen.
Expected
- The last server database is offered as the main action.
Result
Status: ✅ PASS
Comments:
R11AC-495 ✅ PASS
“New file replaces this database” notice disappears after unlocking
Steps
- Open a database over an existing one (staged replacement).
- Unlock successfully.
- Check that the notice is gone.
Expected
- Notice disappears after unlocking.
Result
Status: ✅ PASS
Comments:
R12AC-458Sev-3 ✅ PASS
(One UI 7) Autofill test page follows the app language
Setup needed: Samsung device with One UI 7.
Steps
- Set a non-system app language.
- Open Settings → Autofill test.
- Check the page language and the app language after leaving.
Expected
- Autofill test page follows the app language.
Result
Status: ✅ PASS
Comments:
R13AC-475Sev-3 ✅ PASS
Clipboard “Clear now” on Samsung — no app defect
Design: true
Steps
- Copy a password on a Samsung device.
- Pull down the full notification panel.
- Find the Password Depot notification and use “Clear now”.
Expected
- The “Clear now” action is available in the notification.
- Keyboard clipboard and Samsung overlay are outside the app — do not report as a bug.
Result
Status: ✅ PASS
Comments:
Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)
Estimated time: 45–60 minutes. Run on every device you test.
A1 ✅ PASS
First Launch & Database Creation
Steps
- Fresh install (or update): open the app.
- Create a database with a name and a test master password.
- Confirm the empty entry list is shown.
- Relaunch the app.
- Enter the master password; confirm unlock.
- Enter a wrong master password.
Expected
- Empty list shown after creation.
- After relaunch, app is locked.
- Correct password unlocks; wrong password gives a clear error message.
Result
Status: ✅ PASS
Comments:
A2 ✅ PASS
Entries of Several Types
Steps
- Create the following entries: password entry (with URL of a test account), credit card (PIN/CVV), identity entry, information entry, entry with a protected custom field.
- While typing secret fields (password, PIN, CVV, protected values), verify keyboard behavior.
- Open detail view for each entry.
- Edit each entry and re-save.
Expected
- Secret fields use a password keyboard: no word suggestions, no swipe input; keyboard must not “learn” the value.
- Detail view shows values readable (matching Windows).
- Nothing lost after edit and save.
Result
Status: ✅ PASS
Comments:
A3 ✅ PASS
Folders, Search, Trash
Steps
- Create two folders.
- Move entries between them.
- Search by title, username, and URL.
- Delete an entry (move to trash).
- Restore it from the recycle bin.
Expected
- All operations complete without errors.
- Restored entry appears back in its original location.
Result
Status: ✅ PASS
Comments:
A4 ✅ PASS
Locking
Steps
- Background the app and return quickly (within the auto-lock time).
- Stay away past the auto-lock time (Settings → Security → Auto-lock).
- Force-close the app from Recents.
- Relaunch.
Expected
- Quick background: app stays open.
- After timeout: app is locked.
- After force-close: next start is always locked.
Result
Status: ✅ PASS
Comments:
A5 ✅ PASS
Biometric Unlock + Invalidation
Steps
- Enable Settings → Security → Biometric unlock.
- Lock the database.
- Unlock using fingerprint/face.
- Go to Android system settings and enroll an additional fingerprint.
- Return to the app.
Expected
- Biometric unlock works in step 3.
- After enrolling new fingerprint: app refuses biometrics with an explanation (“biometrics were reset…”), requires master password, database remains fully intact.
- Can re-enable biometric unlock afterwards.
Result
Status: ✅ PASS
Comments:
A6 ✅ PASS
Clipboard
Steps
- Copy a password from the detail view.
- Check if a countdown notification appears (Android 13+: grant notification permission if asked).
- Paste the password in another app — confirm it works.
- Wait 30 seconds; attempt to paste again.
- Try the “Clear now” button in the notification.
- Check the keyboard’s own clipboard history (Samsung/Gboard/SwiftKey).
Expected
- Countdown notification appears immediately.
- Password can be pasted within 30 seconds.
- After 30 seconds: password can no longer be pasted (usernames/URLs: 60 s).
- “Clear now” clears immediately.
- Note: keyboard clipboard history (outside the app’s control) may still show the value — document this, do NOT report as a bug.
Result
Status: ✅ PASS
Comments:
A7 ✅ PASS
Autofill in Your Daily Browser
Note: ⚠️ Chrome 131+ extra step required: Chrome → Settings → Autofill services → “Autofill using another service” → restart Chrome. Older Chrome reaches Password Depot only in an unreliable compatibility mode — please update Chrome.
Steps
- Enable Settings → Autofill service (follow system dialogs).
- Open Settings → Autofill test; confirm the suggestion appears on the built-in test form.
- Navigate to a test account login page in your browser.
- Verify autofill suggestion appears (inline chip or system sheet).
- Fill with Password Depot; confirm fields are filled correctly.
- Log in with a new credential typed manually; confirm save/update prompt appears.
- Negative check: navigate to a different or look-alike domain; confirm the entry is NOT offered under “Matching this site”.
Expected
- Suggestion appears on matching domain.
- Save/update flow works.
- No suggestion offered for non-matching domains.
Result
Status: ✅ PASS
Comments:
A8 ✅ PASS
Autofill in One App
Steps
- Open any app with a login screen (use a test account).
- Trigger autofill.
- Test an app using Android Credential Manager (e.g. Facebook) if available.
Expected
- Autofill works or cleanly offers nothing — no crash, no wrong entry offered.
- Credential Manager apps: system sheet offers the matching entry when Digital Asset Links are published; otherwise “No entry for …” message (no crash).
Result
Status: ✅ PASS
Comments:
A9 ✅ PASS
Appearance, Language, Rotation, Tablet
Steps
- Switch appearance: dark → light → system mode.
- Switch app language DE ↔ EN (Settings → App language on Android 13+).
- Rotate the device while unlocked; confirm session and selection survive.
- (Tablet/foldable only) Verify the two-pane list+detail layout.
- Note any clipped, untranslated, or oddly-worded text.
Expected
- All appearance/language switches work without restart.
- Rotation preserves state.
- Two-pane layout is correct on tablets.
Result
Status: ✅ PASS
Comments:
A10 ✅ PASS
Stability & Error Visibility
What to test: What to watch for throughout testing: any crash or ANR (app not responding); any freeze that requires a force-close; any error that is swallowed silently (action appears to work but data is wrong).
Steps
- If any of the above occur, open Support data immediately (lock → “Support data…” on unlock screen).
- Copy the version line and any listed events.
- File a Jira Bug with Sev-0 and attach the support data.
Expected
- No crashes, freezes, or silently swallowed errors.
Result
Status: ✅ PASS
Comments:
Part 3 — Focus Blocks C1–C11
Complete the blocks assigned to you, or any you have the setup for.
C1 ❌ FAIL
TOTP
Setup needed: A test account with 2FA / TOTP setup, and a reference authenticator app.
Steps
- Add a TOTP secret to a test entry using the entry editor.
- Use “Scan QR code” (camera or photo) to add the TOTP secret — test the QR scanner.
- Compare the 6-digit code with a reference authenticator for at least 3 consecutive periods.
- With autofill: open the 2FA field on a login page; confirm the code is offered only into the one-time-code field.
- Confirm the code is never offered into user/password fields.
Expected
- Codes match the reference authenticator for ≥3 periods.
- Code offered only into OTP fields.
- QR scanner works with camera and photo; invalid QR code rejected with message.
Result
Status: ❌ FAIL
Tested device: Galaxy S22, Android 15
Comments:
C2 ✅ PASS
Passkeys (Android 14+)
Setup needed: Android 14+, device screen lock enabled. Test site: https://webauthn.io
Steps
- Settings → Passkey provider → select Password Depot. Verify the row shows “Enabled”.
- On webauthn.io: register a new passkey (should land in the Password Depot database).
- Sign in with the passkey using the same database.
- Move the passkey entry to the trash.
- Attempt sign-in again → expect “No matching passkey in the database”.
- Restore the passkey entry.
- Attempt sign-in again → confirm it works.
Expected
- All steps above behave as described.
- If sign-in fails at any point, attach the support bundle.
Result
Status: ✅ PASS
Comments:
C3 ✅ PASS
WebDAV Sync
Setup needed: A real Nextcloud and/or Apache WebDAV server over HTTPS.
Steps
- Link the WebDAV server (Settings → Storage location & sync).
- Perform the initial database upload.
- Edit an entry on Android; sync; verify on Windows.
- Edit the same entry on both Android and Windows simultaneously.
- Sync from Android.
Expected
- Initial upload succeeds.
- Single-side edits merge without data loss.
- Concurrent edit on same entry: a conflicted copy appears on Android; original is untouched; conflict can be marked as resolved; nothing lost silently.
- Note the server product + version and whether the account reports safe concurrent writes.
Result
Status: ✅ PASS
Comments:
C4 ✅ PASS
Windows Interop
Setup needed: Windows Password Depot 19 and the same database accessible on both (file copy or WebDAV).
Steps
- Open the same .pswe file alternately in Windows PD 19 and Android.
- Verify that the following survive both directions (Android→Windows, Windows→Android): entries with umlauts/emoji in titles, folders and sub-folders, attachments, TAN lists (kept in file even though Android does not display them), entry history, custom icons, second-password (“four eyes”) entry.
- Specifically: set an expiry date on Android; open in Windows; confirm the date is preserved.
- Edit the same entry on both sides; sync; confirm a conflict copy appears rather than a silent overwrite.
Expected
- All content survives both directions unchanged.
- Any Windows-visible difference is a top priority report.
Result
Status: ✅ PASS
Comments:
C5 ✅ PASS
Attachments
Steps
- Attach a photo (a few MB) to an entry; reopen and export it; verify the file is intact.
- Attach a PDF (a few MB) to an entry; reopen and export it; verify the file is intact.
- Attempt to attach a file over 25 MB.
Expected
- Photo and PDF attach, export, and open correctly.
- File over 25 MB: refused with a clear message, no crash.
Result
Status: ✅ PASS
Comments:
C6 ✅ PASS
Multi-Database & Master Password Change
What to test: Clarification: the app’s copy of every database lives in the app’s private storage, invisible to file managers by design. “The file must survive” refers to a database at a storage location (a file opened via “Open database file…”, WebDAV or cloud); a database created “on this device” has no external file — removing it deletes the only copy, and the app says so and offers “Export a copy first”.
Steps
- Create a second database; switch between both databases.
- Export a copy of the second database (Settings → Databases & sync → “Export a copy…”, save to Downloads).
- Open that file via “Open database file…” (it appears as “Connected to a storage location”).
- Remove THAT entry from the app — the file in Downloads must still exist — and open it again.
- A database created “on this device”: removing it deletes the only copy; the app must say so and offer “Export a copy first”.
- Note: after “remove from app” the backup copies the app kept for that database are gone too — use a database you do not need for C7.
- Change the master password of a test database.
- Attempt to unlock with the old password.
- Check biometric unlock status.
Expected
- Switching between databases works seamlessly.
- “Remove from app” does not delete the external file.
- Old password is rejected after change.
- Biometric unlock requires re-enabling after a password change.
Result
Status: ✅ PASS
Comments:
C7 ✅ PASS
Backup & Restore
Steps
- Navigate to Databases & sync → Backup copies; create a backup of a test database.
- Make a few changes to the database.
- Restore an earlier backup copy.
- Enter a wrong password during restore; check for throttle (3 s / 10 s delay) and message.
- Enter the correct password; confirm restore.
- Verify the restored state is complete; confirm the previous state was saved as a new backup copy first; confirm the chosen copy is still listed.
- (If database is linked to a storage source) Confirm a notice says the next sync will merge instead of replace.
- Attempt to restore a deliberately corrupted backup file.
Expected
- Correct password restores successfully; current state saved before restore; chosen backup still listed.
- Wrong password: throttle + clear message.
- If linked to storage: merge notice shown.
- Corrupted backup: refused with error; active database untouched.
Result
Status: ✅ PASS
Comments:
C8 ✅ PASS
Enterprise Thin Client
Setup needed: Office test server (Enterprise Server 20).
Steps
- Open the app → “Enterprise server…” on the start screen.
- Enter the server address and port; log in.
- On first connect: verify the TLS fingerprint confirmation dialog appears. Compare the SHA-256 with the server certificate (Windows: Home → PD Enterprise Server → “View server certificate”).
- Confirm server and port are remembered after the first successful login.
- Browse and search entries on the server.
- Edit an entry and save.
- Test sign-in with Windows domain credentials (DOMAIN\user or user@company.com) if AD is available.
Expected
- TLS fingerprint dialog appears on first connect.
- Login succeeds; server/port remembered.
- Browse, search, and edit work.
Result
Status: ✅ PASS
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments:
C9 ❌ FAIL
Enterprise Offline Copy
Setup needed: Enterprise Server 20, TCP port 25020, a database with the offline right granted.
Steps
- Sign in to the server; tap “Save offline copy…” on the database list.
- Enter the server password (2FA accounts get a code field in step 2).
- Tap “Load databases” — confirm the TLS fingerprint once.
- Pick a database; confirm the copy is saved.
- Sign out; tap “Open offline copy” on the login screen; open with the server password.
- Verify the status line reads “Enterprise Server · offline copy”.
- Create/edit an entry offline; note the waiting-changes counter in the status line.
- Settings → Sync… → “Send changes to the server”: certificate question appears inside this screen; enter fingerprint; confirm all changes sent; “Load fresh copy” offered.
- Check: entry the server marks as non-editable → no edit action shown.
- Check: without export/save-as rights → Export and “Save as” are absent.
- Check: “Usable until” date matches the server’s offline period.
- Check: offline copy cannot be linked to cloud/WebDAV storage.
- Enter a wrong server password for an existing copy; confirm the error names the password (not “changes waiting”).
Expected
- All steps above behave as described.
- Report the server version from its console with any failure.
Result
Status: ❌ FAIL
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments:
C10 ❌ FAIL
Enterprise Single Sign-On (OpenID Connect / Entra ID)
Setup needed: Enterprise Server 20 with a configured OpenID Connect or Entra ID sign-in provider; the provider registration must contain the redirect oidc.acebit://password-depot.de/.
Steps
- Choose “Single sign-on (OpenID Connect / Entra ID)” in the Enterprise login; tap “Connect”.
- Complete sign-in in the browser; confirm the app returns to the database list.
- Sign out; use “Sign in with a different account”; confirm the provider prompts for account selection.
- Start a sign-in and cancel it in the browser; confirm the app shows “The sign-in in the browser was cancelled”.
- Sign in with an account the server does not know; expect “The Enterprise Server did not accept the sign-in…”.
- Rotate the device while the browser is open; confirm the sign-in continues.
- Press Home during sign-in and return via the browser.
- (If configured) Test the second factor after sign-in.
Expected
- All scenarios above behave as described.
- Report: provider type (Entra ID or other), server version (19 or 20), and exact error messages.
Result
Status: ❌ FAIL
Tested device: Galaxy S22, Android 15
Comments:
C11 🚫 BLOCKED
Hand-Over of Previous-App Offline Changes
Setup needed: Enterprise Server 20, TCP port 25020. Either a previous-app installation with unsent offline changes, or the prepared file from the dev team.
Steps
- Start with the previous Password Depot for Android app installed and an Enterprise database with unsent offline changes.
- Update to this build; open “Import from previous app”; take the database over.
- Verify the report names the number of unsent changes and says they can be sent from the database.
- “Unlock now”: confirm the note at the top shows the same number.
- Tap “Send to the server…”: port 25020 and database name pre-filled; enter server, account, password.
- On first contact: certificate fingerprint question appears inside the dialog — enter it.
- Confirm the note disappears and the changes are on the server (verify in the Windows client).
- Test with a rejected change (e.g. no delete permission): note stays and names the reason; a later send tries only remaining open changes.
- Confirm the database never silently loses the note.
Expected
- All steps above behave as described.
Result
Status: 🚫 BLOCKED
Environment / blocker info: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Comments:
5 · Device Matrix Contribution
| Dimension | Variant | Covered | Notes |
|---|
| Keyboard |
Gboard |
✅ |
|
| Keyboard |
Samsung Keyboard |
✅ |
|
| Keyboard |
SwiftKey |
✅ |
|
| Browser |
Chrome |
✅ |
|
| Browser |
Edge |
✅ |
|
| Browser |
Firefox |
✅ |
|
| Browser |
Samsung Internet |
❌ |
https://internal.tracker.password-depot.de/browse/AC-494 |
| Autofill style |
Android 11+ inline chips (note which you saw) |
— |
|
| Autofill style |
Android ≤13 dropdown |
— |
|
| Clipboard |
Samsung clipboard behavior |
✅ |
|
| Clipboard |
Pixel clipboard behavior |
✅ |
|
| Clipboard |
Xiaomi clipboard behavior |
✅ |
|
| Biometrics |
Fingerprint |
✅ |
|
| Biometrics |
Face unlock |
✅ |
|
| Biometrics |
Both enrolled |
✅ |
|
| OEM quirks |
Xiaomi/HyperOS battery saver — auto-lock reliable? |
✅ |
|
| OEM quirks |
Samsung battery saver — session killed mid-edit? |
✅ |
|
| Form factor |
Phone |
✅ |
|
| Form factor |
Tablet (≥ 600 dp) |
✅ |
|
| Form factor |
Foldable |
✅ |
|
| Storage |
FTPS / FTPES (new in beta21) |
✅ |
|
| Storage |
HiDrive (new in beta21) |
❌ |
https://internal.tracker.password-depot.de/browse/AC-609 |
6 · Reporting Reference
| Jira Project | Android Client (AC) |
| Issue Type (bugs) | Bug |
| Issue Type (coverage) | Task |
| Affects Version | 20.0.0 |
| Build line | 20.0.0-beta21 (1951) |
| Severity 0 | crash · data loss · lock-out |
| Severity 1 | feature wrong or unusable |
| Severity 2 | wrong, has a workaround |
| Severity 3 | visual / text |
| Deadline | within 10 working days |
| Bug summary format | <area>: <short title> |
| Coverage summary format | Beta coverage: <device> |
Support data: lock the app → tap “Support data…” on the unlock screen. Strictly local, secret-free. Copy version line + events into the issue.