Password Depot for Android — QA Test Report

Build 20.0.0-beta22 (1952) · Round 18 · Merged with 20.0.0-beta21 (1951) / Round 17 and 20.0.0-beta17 (1947) / Round 16 · Generated 9/23/2026, 6:44:53 PM

1 · Environment

Device / AndroidSamsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
KeyboardSamsung Keyboard 5.9.12, Microsoft SwiftKey, Gboard
Browser(s)Chrome 152, Edge 152, Firefox 155
Build line20.0.0-beta22 (1952)
TesterSheva Ma
Date started2026-Sep-22

2 · Summary

BlockTotal✅ Pass❌ Fail🚫 Blocked⏭️ Skip🔄 In Progress⬜ Pending
Part 0 — Round 18 Re-Test: Beta21 Bug Fixes 7 3 2 2 0 0 0
Part 0b — Round 17 Re-Test: Beta17 Bug Fixes (historical) 11 8 1 1 1 0 0
Part 0c — Round 16 Re-Test: Beta15 Bug Fixes (historical) 11 10 1 0 0 0 0
Part 0d — Round 16 New Features (beta17) (historical) 10 10 0 0 0 0 0
Part 0e — Round 14 Re-Test: Beta13 Bug Fixes (historical) 13 13 0 0 0 0 0
Part 1 — Core Pass: A1–A10 (Every Tester, Every Device) 10 10 0 0 0 0 0
Part 3 — Focus Blocks C1–C11 11 9 2 0 0 0 0
Total 73 63 6 3 1 0 0
Items tested / total70 / 73
Pass rate (of decided items)91%
Failures (checklist items)6
Blocked items3
New bugs discovered (manual entry)8
Closed bugs (verified fixed)3
Skipped1

3 · Failures (6)

R18-5 AC-609 WebDAV address with “#” gets its own message
Section: Part 0 — Round 18 Re-Test: Beta21 Bug Fixes
Tested device: Android 14 on Galaxy Z Fold 6
Comments / Jira key: Reopened, issue still reproducible.
R18-7 AC-537 / AC-608 Enterprise Server: one-time codes and 2FA against Server 20
Section: Part 0 — Round 18 Re-Test: Beta21 Bug Fixes
Tested device: Galaxy S22, Android 15, Android 15 on Galaxy S25
Comments / Jira key: Issue is fixed on Chrome and Edge browser, but Firefox browser still has issue, hence reopen it.
R17-4 AC-480 Entries protected with a second password are recognised in the autofill picker
Section: Part 0b — Round 17 Re-Test: Beta17 Bug Fixes (historical)
Tested device: Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-622
S6 AC-487 Category picker in the server editor offers the categories
Section: Part 0c — Round 16 Re-Test: Beta15 Bug Fixes (historical)
Tested device: Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-613
C4 Windows Interop
Section: Part 3 — Focus Blocks C1–C11
Tested device: Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-619
C9 Enterprise Offline Copy
Section: Part 3 — Focus Blocks C1–C11
Tested device: Galaxy S22
Comments / Jira key: https://internal.tracker.password-depot.de/browse/AC-617

3a · New Bugs Discovered (Manual Entry) (8)

Bugs entered manually during this round; not part of the fixed checklist. One finding per entry — copy the Jira key into the tracker.

NEW #1 AC-620 Sev-2 Autofill: Modifying username after autofill and logging in creates a new entry instead of updating existing entry
Tested device: Galaxy S22, Android 15
Description / Steps to reproduce:
Problem Summary:
After autofilling username and password in the chrome browser, if the user changes the username and logs in, Password Depot prompts to update the entry. Clicking Update creates a new entry instead of updating the existing one.
NEW #2 AC-623 Sev-2 Recycle Bin: Add button/option to empty or clean recycle bin
Tested device: NA
Description / Steps to reproduce:
Currently in the Android client Recycle Bin view, there is no option or button to empty/clean the entire recycle bin. Users have to handle items individually.
NEW #3 AC-624 Sev-2 Autofill: Autofill in Edge browser fails to detect target URL (unknown target)
Tested device: Samsung Galaxy S22
Description / Steps to reproduce:
Autofill in Microsoft Edge on Android does not detect the target website URL.
Users see an "unknown target" message, and the matching saved password entry is not automatically suggested.
NEW #4 AC-625 Sev-2 Server DB: TOTP field/code is not displayed in entry details view on Android client
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Description / Steps to reproduce:
Problem Description:
When viewing a password entry stored in an Enterprise Server database on the Android client, the TOTP field and generated one-time code do not display in the entry details view, even though the TOTP secret is configured and working properly on the Windows client.
NEW #5 AC-626 Sev-2 Entry Details: Importance set to "High" is incorrectly displayed as "Low" on Android client
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Description / Steps to reproduce:
Summary / Problem Description:
When an entry is created or updated with its Importance level set to "High" (via Windows client or Server DB), the Android client incorrectly displays the Importance badge as "Low" under the DETAILS section.
NEW #6 AC-627 Sev-2 Entry: Warning message configured on Windows client does not pop up when accessing the entry on Android
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Description / Steps to reproduce:
When accessing an entry with a configured warning message, a warning prompt/dialog should pop up displaying the warning text, requiring user confirmation before displaying details or copying credentials (consistent with the Windows client behavior).
NEW #7 AC-628 Sev-2 Server DB: Redundant "Expires" field displayed in DETAILS block for Credit Card entries created via Windows Client in ES DB
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Description / Steps to reproduce:
The DETAILS block should not display a redundant/empty Expires field for Credit Card entries.
NEW #8 AC-629 Sev-2 Unify entry field/item names across new clients with Windows client
Tested device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Description / Steps to reproduce:
Feature request: Unify entry field/item names across new clients with Windows client

3b · Closed Bugs (Verified Fixed) (3)

Bugs that have already been closed and verified fixed on the build/device named. Logged for the round report and the release notes.

CLOSED #1 AC-440 Sev-2 Android Client becomes slow and laggy when database contains 20,000+ entries
Fixed in build: 20.0.0-beta22 (1952)
Verified on device: — not provided —
Resolution / Verification note:
Verified closed
CLOSED #2 AC-430 Sev-2 SSPI login mode - User Logon Name Format settings do not match expected behavior for Simple, Domain\sAMAccountName, and UPN modes
Fixed in build: 20.0.0-beta22 (1952)
Verified on device: — not provided —
Resolution / Verification note:
Verified closed.
CLOSED #3 AC-333 Sev-2 Better to open a numeric keyboard when input a Service phone filed
Fixed in build: 20.0.0-beta22 (1952)
Verified on device: — not provided —
Resolution / Verification note:
Verified closed.

3c · Blocked Items (3)

Items that could not be executed at all — missing test environment, missing server build, no hardware, etc. Each entry names the blocker.

R18-1 AC-604 Key file of the old app — now visible in every key-file prompt
Section: Part 0 — Round 18 Re-Test: Beta21 Bug Fixes
Environment / blocker info: NA
Blocker / Comments: As upgrade not working based on the signatures issue, hence cannot verify this feature for now.
R18-4 AC-607 Takeover report lists skipped settings by name
Section: Part 0 — Round 18 Re-Test: Beta21 Bug Fixes
Environment / blocker info: NA
Blocker / Comments: As upgrade not working based on the signatures issue, hence cannot verify this feature for now.
R17-8 AC-544 Settings taken over from the old app (needs 19.x migration)
Section: Part 0b — Round 17 Re-Test: Beta17 Bug Fixes (historical)
Environment / blocker info: NA
Blocker / Comments: Update not working, as current beta version is using different signatures, then cannot verify this for now.

3d · Skipped (1)

IDTitleReason
R17-11Invisible: Intune app protection SDK (dormant)Feature is still in progress.

4 · Detailed Results

Part 0 — Round 18 Re-Test: Beta21 Bug Fixes

These bugs were reported in Round 17 / first migration test pass and claimed fixed in beta22. Re-test every one on build 1952.

R18-1AC-604Sev-0 🚫 BLOCKED
Key file of the old app — now visible in every key-file prompt
Setup needed: A real 19.x installation with a key-file database (Olha, script M-07).
What to test: After the update, a database that the old app protected with a key file could not be unlocked: the old app's key files live in a folder the system file picker cannot reach. Every key-file prompt (unlock screen, the unlock window of autofill and passkeys, master-password change, restore) now lists the key files of the old app and reads the chosen one for that unlock only — nothing is copied or stored.
Steps
  1. Install a 19.x build; create/protect a database with a key file.
  2. Update to this build; open the takeover flow.
  3. Open the unlock screen and tap “Choose key file…”.
  4. Verify the key files of the old app are listed.
  5. Pick the correct one; unlock.
  6. Repeat in the autofill window and the passkey dialog.
  7. Change the master password and run a restore; verify the same list appears.
Expected
Result
Status: 🚫 BLOCKED
Environment / blocker info: NA
Comments:
As upgrade not working based on the signatures issue, hence cannot verify this feature for now.
R18-2AC-605Sev-3 ✅ PASS
Key-file wording: “Protected with” vs “Additionally protected with”
What to test: A database protected by a key file alone is labelled “Protected with a key file”; “Additionally protected with a key file” stays for password plus key file (picker, candidate list, prompt).
Steps
  1. Open a key-file-only database; check the wording in the picker, the candidate list and the prompt.
  2. Open a password + key-file database; check the wording in the same three places.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R18-3AC-606Sev-3 ✅ PASS
Names after the takeover
Setup needed: A real 19.x migration.
What to test: A taken-over database is named like its file, without folder and extension; backup copies are named “<name> (backup copy n)”; the header no longer shows the file extension.
Steps
  1. Migrate a database from 19.x with a long path and extension.
  2. Check the name in the database list.
  3. Create a backup copy; check its name.
  4. Open the database and check the header.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R18-4AC-607Sev-3 🚫 BLOCKED
Takeover report lists skipped settings by name
Setup needed: A real 19.x installation with an invalid setting (e.g. an auto-lock value not supported by the new app).
What to test: Old settings skipped because of an invalid value are listed by name (auto-lock, appearance, …) instead of a count.
Steps
  1. Migrate from 19.x with at least one invalid setting.
  2. Open the takeover report.
  3. Observe how skipped settings are listed.
Expected
Result
Status: 🚫 BLOCKED
Environment / blocker info: NA
Comments:
As upgrade not working based on the signatures issue, hence cannot verify this feature for now.
R18-5AC-609Sev-2 ❌ FAIL
WebDAV address with “#” gets its own message
Setup needed: HiDrive account (or a similar WebDAV address with “#”).
What to test: Pasting the browser address of the HiDrive web interface (it contains “#”) now gets its own message that says what to enter instead of a generic error.
Steps
  1. Open “Open from cloud…” / “Storage location & sync”.
  2. Paste the browser address of the HiDrive web interface (contains “#”).
  3. Observe the message.
Expected
Result
Status: ❌ FAIL
Tested device: Android 14 on Galaxy Z Fold 6
Comments:
Reopened, issue still reproducible.
R18-6AC-610Sev-3 ✅ PASS
Autofill hint names the app's auto-lock value
What to test: The hint “keep unlocked for …” in the autofill settings names the app's auto-lock and shows its value when the auto-lock is shorter than the reuse window.
Steps
  1. Set the app auto-lock to a value shorter than the reuse window.
  2. Open Settings → Autofill & passkeys; find the hint “keep unlocked for …”.
  3. Observe the hint text.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R18-7AC-537 / AC-608Sev-1 ❌ FAIL
Enterprise Server: one-time codes and 2FA against Server 20
Setup needed: Enterprise Server 20 (only). Server 19 is out of scope for these two.
What to test: With Enterprise Server 20, autofill fills user name, password and the one-time code from a server database, and a two-factor sign-in reports the exact reason (e-mail could not be sent, no e-mail address on the account, authenticator enrolment). A Server 19 cannot supply one-time codes and answers two-factor failures with a plain “sign-in failed” — that is server behaviour, not an app error.
Steps
  1. Sign in to Enterprise Server 20.
  2. Trigger autofill on a site matching a server entry with a one-time code.
  3. Verify user name, password and the current one-time code are filled.
  4. Trigger a 2FA failure; observe the exact reason reported.
  5. Trigger the other 2FA failure variants (no e-mail on the account, authenticator enrolment).
Expected
Result
Status: ❌ FAIL
Tested device: Galaxy S22, Android 15, Android 15 on Galaxy S25
Comments:
Issue is fixed on Chrome and Edge browser, but Firefox browser still has issue, hence reopen it.

Part 0b — Round 17 Re-Test: Beta17 Bug Fixes (historical)

These bugs were reported in Round 16 and claimed fixed in beta21. Kept for regression coverage — re-test if you have the setup or if a round-18 fix touches the same area.

R17-1AC-539Sev-1 ✅ PASS
Firefox shows “Fill in with Password Depot” again
Steps
  1. Enable Settings → Autofill service.
  2. Open a login page in Firefox with a saved matching entry.
  3. Trigger autofill / tap in the login field.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-2AC-538Sev-2 ✅ PASS
Server DB: manually loaded entries stay listed while search box is empty
Known issue / note: Partial fix — the full Edge case stays open.
Steps
  1. Open an Enterprise Server database in the app.
  2. Trigger autofill; load entries manually.
  3. Clear the search box and observe whether the entries remain listed.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-3AC-540Sev-3 ✅ PASS
Permanent setup banner on Android 14 no longer sticks
Known issue / note: Partial fix.
Steps
  1. Set up autofill on Android 14.
  2. Dismiss the setup banner.
  3. Navigate back to the home screen.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-4AC-480Sev-1 ❌ FAIL
Entries protected with a second password are recognised in the autofill picker
Steps
  1. Create an entry with a second password.
  2. Trigger autofill on a matching site.
  3. Tap the protected entry in the picker.
Expected
Result
Status: ❌ FAIL
Tested device: Galaxy S22
Comments:
https://internal.tracker.password-depot.de/browse/AC-622
R17-5AC-541Sev-1 ✅ PASS
Clipboard countdown no longer loops; clipboard is really cleared
Setup needed: Galaxy S26 Ultra / Android 16 (Sheva please re-test).
Steps
  1. Copy a password from the detail view.
  2. Observe the countdown notification.
  3. Wait until the countdown reaches zero.
  4. Attempt to paste the password in another app.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-6AC-517Sev-1 ✅ PASS
Passkeys on a server database stay in that database
Steps
  1. Open a server database in the app.
  2. Create a passkey on a website (webauthn.io or another test site).
  3. Check in which database the passkey landed.
  4. Switch to the local database and check there too.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-7AC-542Sev-2 ✅ PASS
Entry icons for types without a URL field
Steps
  1. Open an entry type without a URL field (e.g. Identity, Information, PuTTY).
  2. Open the icon picker.
  3. Type a web address; load the icon.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-8AC-544Sev-1 🚫 BLOCKED
Settings taken over from the old app (needs 19.x migration)
Setup needed: A real 19.x installation to migrate from.
Steps
  1. Install a 19.x build with custom lock timeout, appearance, and master-password policy.
  2. Update to this build and run “Import from previous app”.
  3. Check the takeover report.
  4. Verify lock timeout, appearance, master-password policy.
  5. Verify biometric unlock is offered per database after first unlock.
Expected
Result
Status: 🚫 BLOCKED
Environment / blocker info: NA
Comments:
Update not working, as current beta version is using different signatures, then cannot verify this for now.
R17-9AC-543Sev-1 ✅ PASS
New storage locations: FTPS/FTPES and HiDrive
Setup needed: Your own FTPS server, or ask for the test server.
Steps
  1. Open “Open from cloud…” or “Storage location & sync”.
  2. Add an FTPS/FTPES server.
  3. On first contact, compare the certificate fingerprint question.
  4. Verify the fingerprint matches the server’s.
  5. Add HiDrive as a provider; verify the row says “HiDrive”.
  6. Verify OneDrive row says “personal or business account (OneDrive for Business)”.
  7. Verify no plain FTP option exists.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-10AC-458Sev-3 ✅ PASS
Language: Early Android 15 no longer keeps Chinese texts
Setup needed: Galaxy S22 / One UI 7 confirmation wanted.
Steps
  1. Set system language to Chinese.
  2. Set app language to English.
  3. Switch system language back to English.
  4. Observe app texts.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R17-11AC-545Sev-1 ⏭️ SKIP
Invisible: Intune app protection SDK (dormant)
Steps
  1. Note start-up time and behaviour on first launch.
  2. Use autofill, passkeys and normal flows.
  3. Watch for any unexpected network or sign-in prompt.
Expected
Result
Status: ⏭️ SKIP
Comments:
Feature is still in progress.

Part 0c — Round 16 Re-Test: Beta15 Bug Fixes (historical)

These bugs were reported in Round 14 and claimed fixed in beta17. Kept for regression coverage.

S1AC-523Sev-1 ✅ PASS
An expired Enterprise Server session really ends the session
Steps
  1. Sign in to Enterprise Server.
  2. Wait ~10 minutes without server traffic.
  3. Try to open or copy an entry.
  4. Open the editor, make a change, wait for expiry, then attempt to save.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S2AC-526Sev-1 ✅ PASS
Unlocking a local or cloud database makes autofill use it
Steps
  1. First open an Enterprise Server database, then lock it.
  2. Unlock a local or cloud database.
  3. Trigger autofill in a browser.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S3AC-527 ✅ PASS
Cloud account shows as connected right after sign-in
Steps
  1. Open Settings → Databases & sync → Cloud accounts.
  2. Sign in to a cloud provider.
  3. Return to Cloud accounts.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S4AC-530 ✅ PASS
“File already exists” appears immediately when picking an existing database
Steps
  1. Open from cloud / Open database file… and pick a file that already exists in the app.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S5AC-480 ✅ PASS
Server entry protected by a second password is marked in autofill
Steps
  1. Create a server entry with a second password.
  2. Trigger autofill on a matching site.
  3. Tap the marked entry.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S6AC-487 ❌ FAIL
Category picker in the server editor offers the categories
Steps
  1. Open a server entry in the editor.
  2. Open the category picker.
Expected
Result
Status: ❌ FAIL
Tested device: Galaxy S22
Comments:
https://internal.tracker.password-depot.de/browse/AC-613
S7AC-458Sev-3 ✅ PASS
App language wraps all 14 windows (incl. autofill and passkey dialogs)
Setup needed: Galaxy S22 with system language in Chinese.
Steps
  1. Set the app language to a non-system language.
  2. Open the autofill window and the passkey dialogs.
  3. Verify all text follows the app language.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S8AC-493 / AC-494 ✅ PASS
Pinned browser without a web address is no longer treated as a native app
Setup needed: Edge and Samsung Internet installed and pinned.
Steps
  1. Open Edge or Samsung Internet with no web address.
  2. Trigger autofill.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S9AC-517 ✅ PASS
Passkeys of an open Enterprise Server database are offered before the local ones
Setup needed: Chrome 131 or newer.
Steps
  1. Open the Enterprise Server database in the app.
  2. Trigger a passkey sign-in in Chrome 131+ on a site matching both databases.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S10AC-522Sev-3 ✅ PASS
Server mode navigation rail: first item is “Home”, no search
Steps
  1. Switch to server mode on a tablet (or wide layout).
  2. Observe the navigation rail.
Expected
Result
Status: ✅ PASS
Comments:
— none —
S11AC-524Sev-0 ✅ PASS
Home screen no longer reads autofill setup state without a safety net (Xiaomi crash)
Setup needed: Xiaomi device.
Steps
  1. Open the app on a Xiaomi device.
  2. Check for any crash on the home screen.
  3. If it crashes, attach the device log.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 0d — Round 16 New Features (beta17) (historical)

New in beta17. Kept for regression coverage.

T1AC-508Sev-0 ✅ PASS
Entries with a second password can be edited again
⭐ Big feature: ⭐ THE BIG ONE from Round 16 — the previous Android app 19.x could do this; 20.0.0 could not until beta17.
Steps
  1. Open an entry with a second password.
  2. Unlock it with its second password.
  3. Edit its user name and/or password; save.
  4. Verify values go back under the same second password without asking again.
  5. On an unprotected entry: set a second password (enter twice), then change it, then remove it.
  6. Open the same database in Password Depot for Windows and check the entry there.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T2AC-528 / AC-529Sev-1 ✅ PASS
Cloud accounts — account switch end to end
Steps
  1. Open Settings → Databases & sync → Cloud accounts.
  2. Sign out a connected provider.
  3. Sign in again; verify the provider lets you pick a different account.
  4. Open a database of account 1 while account 2 is connected.
  5. Reproduce with Dropbox, OneDrive, and Google Drive.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T3AC-514 / AC-510 ✅ PASS
Entry editor — pinned Save header + Symbol row after URL rows
Steps
  1. Open a long form entry editor and scroll to the bottom.
  2. Verify the Save header stays pinned.
  3. For a type with URLs: verify the Symbol row sits after the URL rows.
  4. For a type without URLs: verify the Symbol row is where it was.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T4AC-534Sev-0 ✅ PASS
Key files — unlock always asks explicitly (no silent copies)
Setup needed: A database protected by a key file.
Steps
  1. Unlock a key-file-protected database.
  2. Verify the app asks for the key file explicitly.
  3. Check Settings for any stored key-file copy; revoke if present.
  4. Export a key file; verify the file is read back and the export policy is obeyed.
  5. Test unlock, backup and restore.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T5AC-532Sev-3 ✅ PASS
Unlock error messages with a key file
Steps
  1. Attempt unlock with a wrong key file only.
  2. Attempt unlock with a wrong password plus a key file.
  3. Attempt unlock with a wrong password only.
  4. Repeat the same in the autofill window and the passkey dialog.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T6AC-477 ✅ PASS
Autofill can optionally keep one unlock for a short while (OFF by default)
Design: true
Steps
  1. Turn the option on in the settings.
  2. Authenticate once; fill an entry.
  3. Fill another entry within the window; verify no re-auth prompt.
  4. Wait past the window; verify re-auth is required.
  5. Lock the device or app; verify the window is revoked immediately.
  6. Turn the option back off (default).
Expected
Result
Status: ✅ PASS
Comments:
— none —
T7AC-468Sev-1 ✅ PASS
Entry layouts now follow the Windows client
Setup needed: Windows Password Depot 20 with the same database.
Steps
  1. Open a local entry and a server entry of the same type side by side with Windows.
  2. Compare field order and grouping per type.
  3. Open a Banking entry; verify expiry is MM/YYYY.
  4. Add a field the app does not know on Windows; save on Android; verify it is preserved.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T8AC-512Sev-1 ✅ PASS
Server editor: TOTP set / change / remove
Setup needed: Enterprise Server with ES-990.
Steps
  1. Open a server entry in the editor.
  2. Set a TOTP secret; save.
  3. Change the TOTP secret; save.
  4. Remove the TOTP secret; save.
  5. Open an unsaved server entry; verify TOTP setup only appears after the first save.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T9AC-535 / AC-533Sev-2 ✅ PASS
Cloud accounts — Dropbox real name + account mismatch notice
Steps
  1. Sign in to Dropbox; verify the real account name is shown.
  2. Trigger an account mismatch; verify the notice can be dismissed.
  3. Trigger an unlock error; switch database slots or go to settings; verify the error disappears.
Expected
Result
Status: ✅ PASS
Comments:
— none —
T10AC-497Sev-2 ✅ PASS
Enterprise sign-in — precise e-mail messages keep wording under SSO
Setup needed: Enterprise Server with an SSO-configured sign-in provider.
Steps
  1. Attempt sign-in with an unknown e-mail address under SSO.
  2. Attempt sign-in with a blocked e-mail address under SSO.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 0e — Round 14 Re-Test: Beta13 Bug Fixes (historical)

These bugs were reported in Round 13 and claimed fixed in beta15. Kept for regression coverage.

R1AC-496Sev-0 ✅ PASS
Crash “Placement happened before lookahead” in list/detail layout
Steps
  1. Repeat both step sequences from the original report on a Galaxy S22 with a cloud database.
  2. Open the list, open a detail, navigate back and forth, rotate and switch panes.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R2AC-505 ✅ PASS
Leaving the server mode no longer signs you out
Steps
  1. Sign in to Enterprise Server.
  2. Navigate Enterprise → entries, search, settings → Enterprise, then back.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R3AC-506 / AC-507 ✅ PASS
WebDAV errors now name the HTTP status
Steps
  1. Trigger a WebDAV error.
  2. Observe the error message.
  3. Check the support data for the recorded HTTP status.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R4AC-515 ✅ PASS
Samsung keyboard “https://” suggestion no longer leaves a space
Steps
  1. Open an entry editor with a URL field.
  2. Use the Samsung keyboard’s “https://” suggestion.
  3. Check the resulting value for a stray space.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R5AC-516 ✅ PASS
Chrome 131+ save dialog appears with the page change
Setup needed: A device with Chrome 131+.
Steps
  1. Log in on a test page in Chrome 131+ with a credential typed manually.
  2. Watch for the Password Depot save dialog as the page changes.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R6AC-518 / AC-519 ✅ PASS
Information entries in the server editor use Markdown
Steps
  1. Open an Information entry on the server in the editor.
  2. Check that there is a Markdown content editor and no separate comment field.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R7AC-520 ✅ PASS
Credit-card expiry 05/2026 stays 05/2026
Steps
  1. Create or edit a credit card entry with expiry 05/2026.
  2. Save, reopen, and check the stored value.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R8AC-521 ✅ PASS
PuTTY entries show “Key password”
Steps
  1. Create or open a PuTTY entry.
  2. Check the label of the key password field.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R9AC-487 ✅ PASS
New database starts with Windows default categories
Steps
  1. Create a new database.
  2. Open an entry editor and open the category picker.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R10AC-483 ✅ PASS
Start screen offers last server database when no local database exists
Steps
  1. Remove all local databases from the app (or use a fresh install).
  2. Open the app; observe the start screen.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R11AC-495 ✅ PASS
“New file replaces this database” notice disappears after unlocking
Steps
  1. Open a database over an existing one (staged replacement).
  2. Unlock successfully.
  3. Check that the notice is gone.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R12AC-458Sev-3 ✅ PASS
(One UI 7) Autofill test page follows the app language
Setup needed: Samsung device with One UI 7.
Steps
  1. Set a non-system app language.
  2. Open Settings → Autofill test.
  3. Check the page language and the app language after leaving.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R13AC-475Sev-3 ✅ PASS
Clipboard “Clear now” on Samsung — no app defect
Design: true
Steps
  1. Copy a password on a Samsung device.
  2. Pull down the full notification panel.
  3. Find the Password Depot notification and use “Clear now”.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)

Estimated time: 45–60 minutes. Run on every device you test.

A1 ✅ PASS
First Launch & Database Creation
Steps
  1. Fresh install (or update): open the app.
  2. Create a database with a name and a test master password.
  3. Confirm the empty entry list is shown.
  4. Relaunch the app.
  5. Enter the master password; confirm unlock.
  6. Enter a wrong master password.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A2 ✅ PASS
Entries of Several Types
Steps
  1. Create the following entries: password entry (with URL of a test account), credit card (PIN/CVV), identity entry, information entry, entry with a protected custom field.
  2. While typing secret fields (password, PIN, CVV, protected values), verify keyboard behavior.
  3. Open detail view for each entry.
  4. Edit each entry and re-save.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A3 ✅ PASS
Folders, Search, Trash
Steps
  1. Create two folders.
  2. Move entries between them.
  3. Search by title, username, and URL.
  4. Delete an entry (move to trash).
  5. Restore it from the recycle bin.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A4 ✅ PASS
Locking
Steps
  1. Background the app and return quickly (within the auto-lock time).
  2. Stay away past the auto-lock time (Settings → Security → Auto-lock).
  3. Force-close the app from Recents.
  4. Relaunch.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A5 ✅ PASS
Biometric Unlock + Invalidation
Steps
  1. Enable Settings → Security → Biometric unlock.
  2. Lock the database.
  3. Unlock using fingerprint/face.
  4. Go to Android system settings and enroll an additional fingerprint.
  5. Return to the app.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A6 ✅ PASS
Clipboard
Steps
  1. Copy a password from the detail view.
  2. Check if a countdown notification appears (Android 13+: grant notification permission if asked).
  3. Paste the password in another app — confirm it works.
  4. Wait 30 seconds; attempt to paste again.
  5. Try the “Clear now” button in the notification.
  6. Check the keyboard’s own clipboard history (Samsung/Gboard/SwiftKey).
Expected
Result
Status: ✅ PASS
Comments:
— none —
A7 ✅ PASS
Autofill in Your Daily Browser
Note: ⚠️ Chrome 131+ extra step required: Chrome → Settings → Autofill services → “Autofill using another service” → restart Chrome. Older Chrome reaches Password Depot only in an unreliable compatibility mode — please update Chrome.
Steps
  1. Enable Settings → Autofill service (follow system dialogs).
  2. Open Settings → Autofill test; confirm the suggestion appears on the built-in test form.
  3. Navigate to a test account login page in your browser.
  4. Verify autofill suggestion appears (inline chip or system sheet).
  5. Fill with Password Depot; confirm fields are filled correctly.
  6. Log in with a new credential typed manually; confirm save/update prompt appears.
  7. Negative check: navigate to a different or look-alike domain; confirm the entry is NOT offered under “Matching this site”.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A8 ✅ PASS
Autofill in One App
Steps
  1. Open any app with a login screen (use a test account).
  2. Trigger autofill.
  3. Test an app using Android Credential Manager (e.g. Facebook) if available.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A9 ✅ PASS
Appearance, Language, Rotation, Tablet
Steps
  1. Switch appearance: dark → light → system mode.
  2. Switch app language DE ↔ EN (Settings → App language on Android 13+).
  3. Rotate the device while unlocked; confirm session and selection survive.
  4. (Tablet/foldable only) Verify the two-pane list+detail layout.
  5. Note any clipped, untranslated, or oddly-worded text.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A10 ✅ PASS
Stability & Error Visibility
What to test: What to watch for throughout testing: any crash or ANR (app not responding); any freeze that requires a force-close; any error that is swallowed silently (action appears to work but data is wrong).
Steps
  1. If any of the above occur, open Support data immediately (lock → “Support data…” on unlock screen).
  2. Copy the version line and any listed events.
  3. File a Jira Bug with Sev-0 and attach the support data.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 3 — Focus Blocks C1–C11

Complete the blocks assigned to you, or any you have the setup for.

C1 ✅ PASS
TOTP
Setup needed: A test account with 2FA / TOTP setup, and a reference authenticator app.
Steps
  1. Add a TOTP secret to a test entry using the entry editor.
  2. Use “Scan QR code” (camera or photo) to add the TOTP secret — test the QR scanner.
  3. Compare the 6-digit code with a reference authenticator for at least 3 consecutive periods.
  4. With autofill: open the 2FA field on a login page; confirm the code is offered only into the one-time-code field.
  5. Confirm the code is never offered into user/password fields.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C2 ✅ PASS
Passkeys (Android 14+)
Setup needed: Android 14+, device screen lock enabled. Test site: https://webauthn.io
Steps
  1. Settings → Passkey provider → select Password Depot. Verify the row shows “Enabled”.
  2. On webauthn.io: register a new passkey (should land in the Password Depot database).
  3. Sign in with the passkey using the same database.
  4. Move the passkey entry to the trash.
  5. Attempt sign-in again → expect “No matching passkey in the database”.
  6. Restore the passkey entry.
  7. Attempt sign-in again → confirm it works.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C3 ✅ PASS
WebDAV Sync
Setup needed: A real Nextcloud and/or Apache WebDAV server over HTTPS.
Steps
  1. Link the WebDAV server (Settings → Storage location & sync).
  2. Perform the initial database upload.
  3. Edit an entry on Android; sync; verify on Windows.
  4. Edit the same entry on both Android and Windows simultaneously.
  5. Sync from Android.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C4 ❌ FAIL
Windows Interop
Setup needed: Windows Password Depot 19 and the same database accessible on both (file copy or WebDAV).
Steps
  1. Open the same .pswe file alternately in Windows PD 19 and Android.
  2. Verify that the following survive both directions (Android→Windows, Windows→Android): entries with umlauts/emoji in titles, folders and sub-folders, attachments, TAN lists (kept in file even though Android does not display them), entry history, custom icons, second-password (“four eyes”) entry.
  3. Specifically: set an expiry date on Android; open in Windows; confirm the date is preserved.
  4. Edit the same entry on both sides; sync; confirm a conflict copy appears rather than a silent overwrite.
Expected
Result
Status: ❌ FAIL
Tested device: Galaxy S22
Comments:
https://internal.tracker.password-depot.de/browse/AC-619
C5 ✅ PASS
Attachments
Steps
  1. Attach a photo (a few MB) to an entry; reopen and export it; verify the file is intact.
  2. Attach a PDF (a few MB) to an entry; reopen and export it; verify the file is intact.
  3. Attempt to attach a file over 25 MB.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C6 ✅ PASS
Multi-Database & Master Password Change
What to test: Clarification: the app’s copy of every database lives in the app’s private storage, invisible to file managers by design. “The file must survive” refers to a database at a storage location (a file opened via “Open database file…”, WebDAV or cloud); a database created “on this device” has no external file — removing it deletes the only copy, and the app says so and offers “Export a copy first”.
Steps
  1. Create a second database; switch between both databases.
  2. Export a copy of the second database (Settings → Databases & sync → “Export a copy…”, save to Downloads).
  3. Open that file via “Open database file…” (it appears as “Connected to a storage location”).
  4. Remove THAT entry from the app — the file in Downloads must still exist — and open it again.
  5. A database created “on this device”: removing it deletes the only copy; the app must say so and offer “Export a copy first”.
  6. Note: after “remove from app” the backup copies the app kept for that database are gone too — use a database you do not need for C7.
  7. Change the master password of a test database.
  8. Attempt to unlock with the old password.
  9. Check biometric unlock status.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C7 ✅ PASS
Backup & Restore
Steps
  1. Navigate to Databases & sync → Backup copies; create a backup of a test database.
  2. Make a few changes to the database.
  3. Restore an earlier backup copy.
  4. Enter a wrong password during restore; check for throttle (3 s / 10 s delay) and message.
  5. Enter the correct password; confirm restore.
  6. Verify the restored state is complete; confirm the previous state was saved as a new backup copy first; confirm the chosen copy is still listed.
  7. (If database is linked to a storage source) Confirm a notice says the next sync will merge instead of replace.
  8. Attempt to restore a deliberately corrupted backup file.
Expected
Result
Status: ✅ PASS
Tested device: Galaxy S22
Comments:
— none —
C8 ✅ PASS
Enterprise Thin Client
Setup needed: Office test server (Enterprise Server 20).
Steps
  1. Open the app → “Enterprise server…” on the start screen.
  2. Enter the server address and port; log in.
  3. On first connect: verify the TLS fingerprint confirmation dialog appears. Compare the SHA-256 with the server certificate (Windows: Home → PD Enterprise Server → “View server certificate”).
  4. Confirm server and port are remembered after the first successful login.
  5. Browse and search entries on the server.
  6. Edit an entry and save.
  7. Test sign-in with Windows domain credentials (DOMAIN\user or user@company.com) if AD is available.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C9 ❌ FAIL
Enterprise Offline Copy
Setup needed: Enterprise Server 20, TCP port 25020, a database with the offline right granted.
Steps
  1. Sign in to the server; tap “Save offline copy…” on the database list.
  2. Enter the server password (2FA accounts get a code field in step 2).
  3. Tap “Load databases” — confirm the TLS fingerprint once.
  4. Pick a database; confirm the copy is saved.
  5. Sign out; tap “Open offline copy” on the login screen; open with the server password.
  6. Verify the status line reads “Enterprise Server · offline copy”.
  7. Create/edit an entry offline; note the waiting-changes counter in the status line.
  8. Settings → Sync… → “Send changes to the server”: certificate question appears inside this screen; enter fingerprint; confirm all changes sent; “Load fresh copy” offered.
  9. Check: entry the server marks as non-editable → no edit action shown.
  10. Check: without export/save-as rights → Export and “Save as” are absent.
  11. Check: “Usable until” date matches the server’s offline period.
  12. Check: offline copy cannot be linked to cloud/WebDAV storage.
  13. Enter a wrong server password for an existing copy; confirm the error names the password (not “changes waiting”).
Expected
Result
Status: ❌ FAIL
Tested device: Galaxy S22
Comments:
https://internal.tracker.password-depot.de/browse/AC-617
C10 ✅ PASS
Enterprise Single Sign-On (OpenID Connect / Entra ID)
Setup needed: Enterprise Server 20 with a configured OpenID Connect or Entra ID sign-in provider; the provider registration must contain the redirect oidc.acebit://password-depot.de/.
Steps
  1. Choose “Single sign-on (OpenID Connect / Entra ID)” in the Enterprise login; tap “Connect”.
  2. Complete sign-in in the browser; confirm the app returns to the database list.
  3. Sign out; use “Sign in with a different account”; confirm the provider prompts for account selection.
  4. Start a sign-in and cancel it in the browser; confirm the app shows “The sign-in in the browser was cancelled”.
  5. Sign in with an account the server does not know; expect “The Enterprise Server did not accept the sign-in…”.
  6. Rotate the device while the browser is open; confirm the sign-in continues.
  7. Press Home during sign-in and return via the browser.
  8. (If configured) Test the second factor after sign-in.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C11 ✅ PASS
Hand-Over of Previous-App Offline Changes
Setup needed: Enterprise Server 20, TCP port 25020. Either a previous-app installation with unsent offline changes, or the prepared file from the dev team.
Steps
  1. Start with the previous Password Depot for Android app installed and an Enterprise database with unsent offline changes.
  2. Update to this build; open “Import from previous app”; take the database over.
  3. Verify the report names the number of unsent changes and says they can be sent from the database.
  4. “Unlock now”: confirm the note at the top shows the same number.
  5. Tap “Send to the server…”: port 25020 and database name pre-filled; enter server, account, password.
  6. On first contact: certificate fingerprint question appears inside the dialog — enter it.
  7. Confirm the note disappears and the changes are on the server (verify in the Windows client).
  8. Test with a rejected change (e.g. no delete permission): note stays and names the reason; a later send tries only remaining open changes.
  9. Confirm the database never silently loses the note.
Expected
Result
Status: ✅ PASS
Comments:
— none —

5 · Device Matrix Contribution

DimensionVariantCoveredNotes
Keyboard Gboard ✅
Keyboard Samsung Keyboard ✅
Keyboard SwiftKey ✅
Browser Chrome ✅
Browser Edge ✅
Browser Firefox ✅
Browser Samsung Internet ❌ https://internal.tracker.password-depot.de/browse/AC-494
Autofill style Android 11+ inline chips (note which you saw) ✅
Autofill style Android ≤13 dropdown ✅
Clipboard Samsung clipboard behavior ✅
Clipboard Pixel clipboard behavior ✅
Clipboard Xiaomi clipboard behavior ✅
Biometrics Fingerprint ✅
Biometrics Face unlock ✅
Biometrics Both enrolled ✅
OEM quirks Xiaomi/HyperOS battery saver — auto-lock reliable? ✅
OEM quirks Samsung battery saver — session killed mid-edit? ✅
Form factor Phone ✅
Form factor Tablet (≥ 600 dp) ✅
Form factor Foldable ✅
Storage FTPS / FTPES (new in beta21) ✅
Storage HiDrive (new in beta21) ❌ https://internal.tracker.password-depot.de/browse/AC-609
Migration 19.x migration with key-file database (new in beta22) n/a Part of them passed, but as upgrade not working based on the signatures issue, hence cannot verify this feature for now.

6 · Reporting Reference

Jira ProjectAndroid Client (AC)
Issue Type (bugs)Bug
Issue Type (coverage)Task
Affects Version20.0.0
Build line20.0.0-beta22 (1952)
Severity 0crash · data loss · lock-out
Severity 1feature wrong or unusable
Severity 2wrong, has a workaround
Severity 3visual / text
Deadlinewithin 10 working days
Bug summary format<area>: <short title>
Coverage summary formatBeta coverage: <device>

Support data: lock the app → tap “Support data…” on the unlock screen. Strictly local, secret-free. Copy version line + events into the issue.