Password Depot for Android — RC10 QA Test Report
Build 20.0.0 RC10 (2010) · Release Candidate 10 · Regression of 20.0.0 RC9 · RC9 QA Report · 2026-10-05 · Generated 10/7/2026, 7:06:20 PM
1 · Environment
| Device / Android | Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15 |
|---|
| Keyboard | Gboard |
|---|
| Browser(s) | Chrome 154 |
|---|
| Build line | 20.0.0 RC10 (2010) |
|---|
| Tester | Sheva Ma |
|---|
| Date started | 2026-10-06 |
|---|
2 · Summary
| Block | Total | ✅ Pass/Fixed | ❌ Fail | 🚫 Blocked | ⏭️ Skip | 🔄 In Progress | ⬜ Pending |
|---|
| Part 0 — RC9 FAILURES Re-Test | 1 | 0 | 0 | 0 | 1 | 0 | 0 |
| Part 1 — RC9 NEW BUGS Re-Test | 13 | 2 | 1 | 0 | 10 | 0 | 0 |
| Part 2 — RC9 Blocked Re-Test | 2 | 0 | 0 | 1 | 1 | 0 | 0 |
| Part 3 — RC9 Skipped Re-Test | 1 | 0 | 0 | 0 | 1 | 0 | 0 |
| Part 4 — RC8 NEW BUGS Regression (1) | 1 | 1 | 0 | 0 | 0 | 0 | 0 |
| Part 5 — RC5 NEW BUGS Regression (10) | 10 | 10 | 0 | 0 | 0 | 0 | 0 |
| Part 6 — RC10 Smoke: Google Play Readiness | 7 | 7 | 0 | 0 | 0 | 0 | 0 |
| Part 7 — Security & MDM | 2 | 2 | 0 | 0 | 0 | 0 | 0 |
| Part 8 — RC1 Reported Bugs Regression (10 PASS) | 10 | 10 | 0 | 0 | 0 | 0 | 0 |
| Part 9 — Beta21 / RC1 Regression (R18-1 – R18-7) | 7 | 7 | 0 | 0 | 0 | 0 | 0 |
| Part 10 — Core Pass: A1–A10 (Every Tester, Every Device) | 10 | 10 | 0 | 0 | 0 | 0 | 0 |
| Part 11 — Focus Blocks C1–C11 | 11 | 10 | 0 | 0 | 0 | 1 | 0 |
| Total | 75 | 59 | 1 | 1 | 13 | 1 | 0 |
| Items tested / total | 73 / 75 |
|---|
| Pass rate (of decided items) | 98% |
|---|
| Failures | 1 |
|---|
| Blocked items | 1 |
|---|
| New bugs discovered (manual entry) | 7 |
|---|
| Closed bugs (verified fixed this round) | 0 |
|---|
3a · RC9 FAILURES Re-Test (0)
No RC9 failures re-tested this round. 🎉
3b · RC9 NEW BUGS Re-Test (13)
RC9-N1AC-773Sev-2⏭️ SKIP
UI/UX: Support database switching on tablet portrait and phone — unify database selector in the top bar
RC9 note: Currently, switching between databases is only convenient on tablet landscape. On tablet portrait and phone, there is no unified way to switch databases — the user must navigate back and re-enter the target database.
Tested device: — not provided —
Comments: Not ready for testing.
RC9-N2AC-774Sev-2✅ PASS
Autofill prompt "Save username and password to Password Depot?" appears after SSO login, but the entry is never saved
RC9 note: After SSO login (Entra ID / OpenID Connect), the autofill prompt appears. Tapping Save does not create an entry anywhere; no feedback is given.
Tested device: — not provided —
Comments: — none —
RC9-N3AC-775Sev-2✅ PASS
Refresh button disappears from the top bar when opening an entry detail view
RC9 note: When viewing the entry list, the top bar shows the Refresh button (🔄). Tapping an entry to open its detail view hides the Refresh button; only Settings (⚙️) and Sign out remain.
Tested device: — not provided —
Comments: — none —
RC9-N4AC-777Sev-2⏭️ SKIP
UI/UX: Move Edit and overflow (⋮) buttons to the right side of the entry detail header in tablet portrait mode
RC9 note: In tablet portrait, the Edit button and the overflow (⋮) are positioned on the left side of the detail header, below the title. In tablet landscape they are correctly aligned to the right. Only tablet portrait is in scope.
Tested device: — not provided —
Comments: Not ready for testing.
RC9-N5AC-779Sev-2⏭️ SKIP
UX: Allow selecting a target folder when saving an entry from the browser autofill prompt
RC9 note: When Password Depot offers to save credentials from the browser, the save flow does not allow choosing which folder the new entry is saved into. The entry is saved to the database root / default location.
Tested device: — not provided —
Comments: Not ready for testing.
RC9-N6AC-780Sev-2⏭️ SKIP
UI/UX: Master password policy dialog should apply changes immediately — remove the Save and Cancel buttons
RC9 note: Every other Settings row applies immediately. The Master password policy dialog is the only exception: it shows Save / Cancel buttons.
Tested device: — not provided —
Comments: Not ready for testing.
RC9-N7AC-782Sev-2⏭️ SKIP
UI/UX: Replace chevron with an action icon on "Create backup copy now" and show a success/failure toast after the action
RC9 note: In Settings → Backup copies, "Create backup copy now" shows a chevron (>) like a navigation row, but it performs an action. No feedback after tapping.
Tested device: — not provided —
Comments: Not ready for testing.
RC9-N8AC-783Sev-2⏭️ SKIP
UI/UX: Replace the "Number of stored copies" dialog with an inline stepper control (− / input / +) in Settings
RC9 note: "Number of stored copies" opens a separate dialog to edit a single numeric value. An inline stepper would be faster and consistent with other numeric settings.
Tested device: — not provided —
Comments: Not ready for testing.
RC9-N9AC-791Sev-2⏭️ SKIP
UX: Autofill only searches the server DB when both a local DB and a server DB are unlocked — should search both, or prioritise the most recently opened DB
RC9 note: When both a local DB and a server DB are unlocked, autofill only searches the server DB, regardless of which DB was opened most recently. Local DB entries are never offered.
Tested device: — not provided —
Comments: Not ready for testing.
RC9-N10AC-814Sev-2⏭️ SKIP
Add search functionality across all database list views (Local, Cloud, Server)
RC9 note: The app does not support search/filter in database list screens. Locating a specific DB when many exist is difficult.
Tested device: — not provided —
Comments: Not ready for testing.
RC9-N11AC-815Sev-2⏭️ SKIP
UI/UX: Use standard accordion chevron directions for "Another way in" section
RC9 note: "Another way in" shows a right chevron (>) when collapsed and a down chevron (v) when expanded. In mobile UX, right chevron indicates drill-down; down arrow does not intuitively convey collapse.
Tested device: — not provided —
Comments: Not ready for testing.
RC9-N12AC-816Sev-2❌ FAIL
Local database: Local database permanently converts to cloud database after syncing, causing blocking timeouts on offline operations
RC9 note: Syncing a local database to cloud storage permanently converts it into a cloud database. Offline work then blocks/hangs until the cloud connection times out.
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Comments: On RC10 build 2010, Snyc always display “Offline” now, even I cliecked “Sync now”, and got “Synced” status, hence reopen the issue.
RC9-N13AC-817Sev-2⏭️ SKIP
Settings: Separate App-level and Database-level Settings in UI and Tablet Navigation
RC9 note: Settings menu mixes database-level and app-level settings into a single flat list, causing confusion about scope. Tablet navigation does not clearly differentiate global vs database-specific settings.
Tested device: — not provided —
Comments: Not ready for testing.
3c · RC9 Blocked Re-Test (2)
RC9-B1SEC-2🚫 BLOCKED
MDM bans (export, cloud, autofill, clipboard) enforced at the sink
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Comments: MDM is disabled.
RC9-B2SEC-3⏭️ SKIP
MDM bans enforced in the autofill / passkey process (from round 5)
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Comments: MDM is disabled.
3d · RC9 Skipped Re-Test (1)
RC9-S1AC-766⏭️ SKIP
Unable to access Server DB Settings on Tablet (Left rail Settings opens Local/Cloud DB settings instead)
Tested device: — not provided —
Comments: This is not ready for test.
3e · Failures on the checklist (1)
RC9-N12AC-816Local database: Local database permanently converts to cloud database after syncing, causing blocking timeouts on offline operations
Section: Part 1 — RC9 NEW BUGS Re-Test
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Comments: On RC10 build 2010, Snyc always display “Offline” now, even I cliecked “Sync now”, and got “Synced” status, hence reopen the issue.
3f · New Bugs Discovered (Manual Entry — this round) (7)
NEW #1AC-824Sev-2WebDAV/HiDrive: Prepend fixed '<redacted URL>' prefix to server address input field
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
Summary
On the “Connect WebDAV server/ HiDrive” screen, the address field should include a fixed, non-editable <redacted URL> prefix. This will make it easier for users to enter the server address, especially on mobile devices.
Context
Users currently need to type the <redacted URL> protocol prefix manually in the address input field on step “2 · Address”. On mobile soft keyboards, this requires switching between keyboard modes to enter : and //, which is inconvenient and can lead to input errors.
Acceptance criteria
The UI visually shows the fixed <redacted URL> scheme prefix.
The scheme prefix is non-editable.
Users only need to enter the domain and file/folder path, such as webdav.example.com/db.pswe.
If a user pastes a full URL that already includes a scheme, the app removes the duplicate scheme prefix.
Validation still enforces secure scheme usage.
Pasting a full URL must not create scheme://scheme://... duplication.
NEW #2AC-825Sev-2Incorrect OpenSSL command under "For administrators" for FTP/FTPES server certificate fingerprint
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
Impact
Users connecting to an FTPS server may see a misleading OpenSSL command in the Confirm server certificate dialog.
This makes it harder for administrators to get the correct SHA-256 certificate fingerprint for FTP/FTPES servers.
Expected behaviour
The command under For administrators for FTP/FTPES should include -starttls ftp and suppress diagnostic output with 2>/dev/null.
Expected command:
openssl s_client -connect <host>:<port> -starttls ftp </dev/null 2>/dev/null | openssl x509 -noout -fingerprint -sha256
Actual behaviour
The command shown is missing -starttls ftp.
Current command:
openssl s_client -connect shevalabs.top:21 </dev/null | openssl x509 -noout -fingerprint -sha256
Steps to reproduce
Connect to an FTPS server, such as Explicit TLS / FTPES on port 21.
Use a server certificate that is not trusted, such as a self-signed certificate.
The Confirm server certificate dialog appears.
Expand the For administrators section.
View the suggested OpenSSL command.
Environment
NEW #3AC-836Sev-2https://internal.tracker.password-depot.de/browse/AC-836
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
Impact
Entries with wildcard masks in the "Additional URL" field are not recognized by Password Depot Autofill.
Users do not get the matching entry suggested when they visit a matching web page. Autofill shows that no matching entry was found.
Expected behaviour
Autofill should evaluate wildcard masks in Additional URLs, such as:
*square.com*
*.domain.com
github.com
It should then automatically suggest the matching entry for autofill.
Actual behaviour
Password Depot Autofill does not identify the entry matching the Additional URL mask.
It shows:
"No entry matches <URL>. The list below is a manual choice only."
The entry is only available through manual search or selection.
Steps to reproduce
In Password Depot Android or the Windows client, create or edit an entry, for example: square.com - juliebrooks34.
Set the main Website: <redacted URL>.
Add an Additional URL containing a wildcard mask, for example: *squareup.com*.
Save the entry.
Click open url icon to open the website.
Tap the username/password input field to trigger Password Depot Autofill.
Unlock the database if prompted.
Environment
NEW #4AC-837Sev-2Server DB: Unable to delete folder / Missing delete option or button inside folder view
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
Impact
Users cannot delete a folder from inside the folder view on the Android client. This blocks folder deletion for users who have the needed permissions.
Expected behaviour
When viewing a folder, users should have a way to delete it. This could be a top bar action or an overflow menu option such as Delete folder, assuming the user has the correct permissions.
Actual behaviour
Inside the folder view, there is no Delete button or overflow menu option. Only the back button, refresh, logout, and + New button are present.
Steps to reproduce
Log into an Enterprise Server database on the Android client.
Navigate into a folder, for example “test folder".
Attempt to delete the folder.
Environment
NEW #5AC-838Sev-2Server DB: Autofill does not respond when clicking an entry configured with a second password
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
Summary / Problem Description
When using an Enterprise Server database on Android, if an entry has a second password configured, selecting/clicking that entry from the autofill bottom sheet ("Select entry" dialog) has no response—it does not prompt for the second password nor autofill any credentials into the webpage.
(Note: The issue is triggered by the entry having a second password protection, rather than TOTP fields on the page).
Steps to Reproduce
Connect and log into an Enterprise Server database on the Android client.
Ensure a database entry has a second password set.
Open a browser and navigate to the matching webpage/login URL.
Trigger autofill to open the "Select entry" bottom sheet / dialog.
Tap on the matching entry that has a second password.
Expected Result
Tapping the entry should prompt the user to enter the second password and, once authenticated, proceed to autofill the credentials into the corresponding fields.
Actual Result
Tapping the entry has no response at all (no second password input prompt appears, and fields are not filled).
Environment
NEW #6AC-839Sev-2[Autofill / Server DB] Session ended error does not show sign-in prompt and loops back to unlock on "Confirm and search"
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
Summary
When an Enterprise Server database session has ended, attempting to autofill in a browser sometimes displays the error: "The Enterprise Server session has ended. Sign in again in Password Depot.", but no sign-in page is prompted. Clicking "Confirm and search" leads into a loop prompting to unlock, and then returns back to this error screen.
Steps to Reproduce
Connect to and open an Enterprise Server database.
Wait for or trigger a session timeout / session ended state for the Server DB.
Open any website in the browser and trigger autofill.
Observe the error message: "The Enterprise Server session has ended. Sign in again in Password Depot." — notice that no sign-in page is displayed.
Tap "Confirm and search".
Observe the unlock prompt, unlock, and see that it returns right back to the session ended error screen.
Expected Behavior
When the session has ended, triggering autofill should prompt or navigate the user to the Server DB sign-in screen to re-authenticate, or successfully authenticate and complete autofill without getting stuck in an unlock loop.
Actual Behavior
No sign-in screen is shown.
Tapping "Confirm and search" triggers an unlock loop, which then redirects back to the "The Enterprise Server session has ended. Sign in again in Password Depot." error screen.
NEW #7AC-841Sev-2SSH/RDP: Recommend supported apps when no compatible client app is installed
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
Summary
When the Android client displays the inactivity expiration warning prompt: "Your session will expire soon due to inactivity — any action keeps it alive. Extend", attempting to trigger autofill in a browser consistently causes the error: "The Enterprise Server session has ended. Sign in again in Password Depot." without prompting a sign-in screen. Tapping "Confirm and search" prompts to unlock, but after unlocking it loops right back to the session ended error screen.
Note: This issue strictly reproduces when the client is currently showing the "expire soon" warning prompt. If the session has already fully expired / logged out, the bug does not occur.
Steps to Reproduce
Connect to and open an Enterprise Server database in the Android client.
Wait for the client to show the inactivity expiration warning: "Your session will expire soon due to inactivity — any action keeps it alive. Extend" (do not allow the session to fully exit/log out).
While this prompt is displayed on the client, switch to a browser on any website and trigger autofill.
Observe the error dialog: "The Enterprise Server session has ended. Sign in again in Password Depot." — notice no sign-in page/prompt is offered.
Tap "Confirm and search".
Complete the unlock prompt (PIN/biometrics).
Notice that after unlocking, it immediately loops back to the "The Enterprise Server session has ended. Sign in again in Password Depot." error screen.
Expected Behavior
Autofill should either extend the active session or properly prompt the user to sign in / re-authenticate to the Enterprise Server database, allowing autofill to proceed without getting stuck in an unlock loop.
Actual Behavior
No Enterprise Server sign-in screen is prompted.
Tapping "Confirm and search" triggers an unlock prompt, which loops straight back to the "The Enterprise Server session has ended. Sign in again in Password Depot." error screen.
3g · Closed Bugs (Verified Fixed — this round) (0)
No closed bugs were logged this round.
3h · Blocked Items (1)
RC9-B1SEC-2MDM bans (export, cloud, autofill, clipboard) enforced at the sink
Section: Part 2 — RC9 Blocked Re-Test
Blocker info: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Comments: MDM is disabled.
3i · Skipped (13)
| ID | Title | Reason |
|---|
| RC9-F1 | [UX/Storage] Support listing databases automatically for WebDAV, FTP, and HiDrive storage instead of requiring full file paths | Not ready for testing. |
| RC9-N1 | UI/UX: Support database switching on tablet portrait and phone — unify database selector in the top bar | Not ready for testing. |
| RC9-N4 | UI/UX: Move Edit and overflow (⋮) buttons to the right side of the entry detail header in tablet portrait mode | Not ready for testing. |
| RC9-N5 | UX: Allow selecting a target folder when saving an entry from the browser autofill prompt | Not ready for testing. |
| RC9-N6 | UI/UX: Master password policy dialog should apply changes immediately — remove the Save and Cancel buttons | Not ready for testing. |
| RC9-N7 | UI/UX: Replace chevron with an action icon on "Create backup copy now" and show a success/failure toast after the action | Not ready for testing. |
| RC9-N8 | UI/UX: Replace the "Number of stored copies" dialog with an inline stepper control (− / input / +) in Settings | Not ready for testing. |
| RC9-N9 | UX: Autofill only searches the server DB when both a local DB and a server DB are unlocked — should search both, or prioritise the most recently opened DB | Not ready for testing. |
| RC9-N10 | Add search functionality across all database list views (Local, Cloud, Server) | Not ready for testing. |
| RC9-N11 | UI/UX: Use standard accordion chevron directions for "Another way in" section | Not ready for testing. |
| RC9-N13 | Settings: Separate App-level and Database-level Settings in UI and Tablet Navigation | Not ready for testing. |
| RC9-B2 | MDM bans enforced in the autofill / passkey process (from round 5) | MDM is disabled. |
| RC9-S1 | Unable to access Server DB Settings on Tablet (Left rail Settings opens Local/Cloud DB settings instead) | This is not ready for test. |
4 · Detailed Results
Part 0 — RC9 FAILURES Re-Test
This is the 1 failure from the RC9 QA Report (2026-10-05, section 3a/3d). AC-736 was reopened on RC9: FTP works, but HiDrive login does not redirect to the WebDAV URL. This is a release blocker.
RC9-F1AC-736Sev-2⏭️ SKIP
[UX/Storage] Support listing databases automatically for WebDAV, FTP, and HiDrive storage instead of requiring full file paths
Setup needed: A WebDAV / FTP / HiDrive account with multiple .pswe databases.
RC9 status: FAIL — RC9: "Verified on RC9 build 2009, FTP works fine now, but the HiDrive has issue to login: HiDrive: if I just input the url: HiDrive Login - Der Online-Speicher für Dateien, Bilder & Musik! , it won’t redirect to https://webdav.hidrive.strato.com, which caused open drive failed to load the folders."
Steps
- Open "Open from cloud…" / "Storage location & sync".
- Add a HiDrive storage location.
- Enter the HiDrive URL as shown in the browser (the portal URL, not the WebDAV URL).
- Check whether the client automatically redirects to https://webdav.hidrive.strato.com.
- Check whether the client automatically lists available .pswe databases.
- Pick one from the list.
Expected
- HiDrive portal URL is recognised and redirected to the correct WebDAV endpoint.
- Available .pswe databases are listed automatically.
- User can select from the list — no full path typing required.
Result
Status: ⏭️ SKIP
Comments:
Part 1 — RC9 NEW BUGS Re-Test
These are the 13 New Bugs discovered in the RC9 QA Report (2026-10-05, section 3e). Each must be re-tested on RC10. This is the highest-priority block.
RC9-N1AC-773Sev-2⏭️ SKIP
UI/UX: Support database switching on tablet portrait and phone — unify database selector in the top bar
Setup needed: A device with at least one Local DB, one Cloud DB, and one Server DB.
RC9 status: OPEN (new #1) — Currently, switching between databases is only convenient on tablet landscape. On tablet portrait and phone, there is no unified way to switch databases — the user must navigate back and re-enter the target database.
Steps
- Open Password Depot on a phone and on a tablet (portrait and landscape).
- Tap the database name area in the top-left of the top bar (e.g., "localdb1002 ▼").
- Verify a unified dropdown opens with Server / Cloud / Local groups.
- Select a different database and verify direct switch (prompt for password if locked).
- On tablet landscape: verify dropdown shows only the relevant subset (server DB list when server DB open; local DB list when local DB open).
- Verify the current database is marked with ✓.
- Verify "Add database…" is available at the bottom.
Expected
- Database name in the top bar is clickable on phone, tablet portrait, and tablet landscape.
- Dropdown lists databases grouped by type (Server / Cloud / Local).
- Selecting a database switches directly to it.
- Current database is marked ✓.
- Dropdown is scrollable and searchable when the list is long.
- "Add database…" entry at the bottom.
Result
Status: ⏭️ SKIP
Comments:
RC9-N2AC-774Sev-2✅ PASS
Autofill prompt "Save username and password to Password Depot?" appears after SSO login, but the entry is never saved
Setup needed: Enterprise Server DB with SSO (Entra ID / OpenID Connect).
RC9 status: OPEN (new #2) — After SSO login (Entra ID / OpenID Connect), the autofill prompt appears. Tapping Save does not create an entry anywhere; no feedback is given.
Steps
- Sign in to an Enterprise Server DB via SSO for the first time.
- Complete the Azure login page in the browser.
- Observe the "Save username and password to Password Depot?" prompt.
- Tap Save.
- Open the server database that was just connected.
- Check for a new entry with the SSO credentials.
- Also check recently opened local databases.
Expected
- Option A — Prompt does not appear if SSO credentials cannot be saved.
- Option B — Prompt appears and the entry is actually saved (preferred target: most recently opened local DB), with a confirmation like "Saved to localdb1002".
Result
Status: ✅ PASS
Comments:
RC9-N3AC-775Sev-2✅ PASS
Refresh button disappears from the top bar when opening an entry detail view
Setup needed: Enterprise Server DB; entry list and entry detail view.
RC9 status: OPEN (new #3) — When viewing the entry list, the top bar shows the Refresh button (🔄). Tapping an entry to open its detail view hides the Refresh button; only Settings (⚙️) and Sign out remain.
Steps
- Sign in to an Enterprise Server DB.
- In the entry list view, confirm the Refresh button is visible in the top bar.
- Tap any entry to open its detail view.
- Observe the top bar.
Expected
- Refresh button remains visible in both entry list and entry detail view.
- User can refresh the database at any time.
Result
Status: ✅ PASS
Comments:
RC9-N4AC-777Sev-2⏭️ SKIP
UI/UX: Move Edit and overflow (⋮) buttons to the right side of the entry detail header in tablet portrait mode
Setup needed: Android tablet in portrait mode; an entry detail view.
RC9 status: OPEN (new #4) — In tablet portrait, the Edit button and the overflow (⋮) are positioned on the left side of the detail header, below the title. In tablet landscape they are correctly aligned to the right. Only tablet portrait is in scope.
Steps
- Open Password Depot on a tablet in portrait mode.
- Open any entry to view its detail.
- Observe the position of the Edit and ⋮ buttons.
Expected
- In tablet portrait, Edit and ⋮ appear on the right side.
- Title and metadata remain left-aligned.
- Layout stable for long titles.
- Tablet landscape unchanged.
Result
Status: ⏭️ SKIP
Comments:
RC9-N5AC-779Sev-2⏭️ SKIP
UX: Allow selecting a target folder when saving an entry from the browser autofill prompt
Setup needed: Browser autofill on a login page.
RC9 status: OPEN (new #5) — When Password Depot offers to save credentials from the browser, the save flow does not allow choosing which folder the new entry is saved into. The entry is saved to the database root / default location.
Steps
- In the browser, log in to a website with a matching saved entry (or a new site).
- Trigger the Password Depot save prompt.
- Check whether a folder selector is available.
- Save the entry and check where it ends up.
- Repeat with the "Replace saved password?" dialog.
Expected
- The "Save to Password Depot" dialog includes a folder selector.
- The "Replace saved password?" dialog also includes a folder selector.
- Selected folder is respected when the entry is created.
- Default is database root or the last used folder.
Result
Status: ⏭️ SKIP
Comments:
RC9-N6AC-780Sev-2⏭️ SKIP
UI/UX: Master password policy dialog should apply changes immediately — remove the Save and Cancel buttons
Setup needed: Settings → Master password policy.
RC9 status: OPEN (new #6) — Every other Settings row applies immediately. The Master password policy dialog is the only exception: it shows Save / Cancel buttons.
Steps
- Open Settings → Master password policy.
- Change Minimum length, Lowercase, Uppercase, Numbers, Special characters.
- Check whether changes apply immediately or require tapping Save.
- Close the dialog without saving to verify no unintended change.
Expected
- No Save / Cancel buttons.
- Changes apply immediately.
- Closing without change leaves policy untouched.
- Consistent with all other Settings entries.
Result
Status: ⏭️ SKIP
Comments:
RC9-N7AC-782Sev-2⏭️ SKIP
UI/UX: Replace chevron with an action icon on "Create backup copy now" and show a success/failure toast after the action
Setup needed: Settings → Backup copies.
RC9 status: OPEN (new #7) — In Settings → Backup copies, "Create backup copy now" shows a chevron (>) like a navigation row, but it performs an action. No feedback after tapping.
Steps
- Open Settings → Backup copies.
- Observe the icon on "Create backup copy now".
- Tap it and observe feedback.
Expected
- Icon replaced with an action icon (e.g., ↻).
- Other rows in the same group keep their > chevron.
- Success toast shown when backup created.
- Failure toast shown when backup fails.
- Last copy timestamp updates.
Result
Status: ⏭️ SKIP
Comments:
RC9-N8AC-783Sev-2⏭️ SKIP
UI/UX: Replace the "Number of stored copies" dialog with an inline stepper control (− / input / +) in Settings
Setup needed: Settings → Backup copies → Number of stored copies.
RC9 status: OPEN (new #8) — "Number of stored copies" opens a separate dialog to edit a single numeric value. An inline stepper would be faster and consistent with other numeric settings.
Steps
- Open Settings → Backup copies.
- Observe the row "Number of stored copies".
- Check whether it opens a dialog or allows inline editing.
Expected
- Row shows an inline stepper: − [ value ] +.
- − and + adjust by 1; disabled at min/max.
- Tapping the input opens the numeric keyboard.
- Changes apply immediately (no Save / Cancel).
Result
Status: ⏭️ SKIP
Comments:
RC9-N9AC-791Sev-2⏭️ SKIP
UX: Autofill only searches the server DB when both a local DB and a server DB are unlocked — should search both, or prioritise the most recently opened DB
Setup needed: Both a local DB and a server DB unlocked simultaneously; a login page matching an entry in the local DB.
RC9 status: OPEN (new #9) — When both a local DB and a server DB are unlocked, autofill only searches the server DB, regardless of which DB was opened most recently. Local DB entries are never offered.
Steps
- Sign in to a server DB and leave it unlocked.
- Also open a local DB and leave it unlocked.
- Switch to the local DB and open an entry in it.
- Open a browser and trigger autofill on a login page matching a local DB entry.
- Observe which entries are offered.
Expected
- Option A — Autofill aggregates results from all unlocked DBs, grouped/labelled by source (preferred).
- Option B — Autofill prioritises the most recently opened DB.
- Source DB of each suggestion is visible.
Result
Status: ⏭️ SKIP
Comments:
RC9-N10AC-814Sev-2⏭️ SKIP
Add search functionality across all database list views (Local, Cloud, Server)
Setup needed: A device with many databases in Local / Cloud / Server lists.
RC9 status: OPEN (new #10) — The app does not support search/filter in database list screens. Locating a specific DB when many exist is difficult.
Steps
- Open the Local database list; look for a search bar/action.
- Open the Cloud database list; look for a search bar/action.
- Open the Server database list; look for a search bar/action.
- Type a keyword; observe filtering.
- Clear the search; verify full list restored.
- Search a non-matching keyword; verify empty state message.
Expected
- Search bar/action available on Local, Cloud, and Server database lists.
- Typing filters in real-time or on submit by database name.
- Clearing restores full list.
- Empty state message when no match.
Result
Status: ⏭️ SKIP
Comments:
RC9-N11AC-815Sev-2⏭️ SKIP
UI/UX: Use standard accordion chevron directions for "Another way in" section
Setup needed: Home screen with "Another way in" section.
RC9 status: OPEN (new #11) — "Another way in" shows a right chevron (>) when collapsed and a down chevron (v) when expanded. In mobile UX, right chevron indicates drill-down; down arrow does not intuitively convey collapse.
Steps
- Open Home screen.
- Collapse "Another way in"; observe chevron direction.
- Expand "Another way in"; observe chevron direction.
- Tap the section to toggle.
Expected
- Collapsed: chevron points down (⌄).
- Expanded: chevron points up (⌃).
- Tapping toggles with matching chevron direction.
Result
Status: ⏭️ SKIP
Comments:
RC9-N12AC-816Sev-2❌ FAIL
Local database: Local database permanently converts to cloud database after syncing, causing blocking timeouts on offline operations
Setup needed: Local DB synced to WebDAV or another cloud storage.
RC9 status: OPEN (new #12) — Syncing a local database to cloud storage permanently converts it into a cloud database. Offline work then blocks/hangs until the cloud connection times out.
Steps
- Create a new local database.
- Sync the database to WebDAV or another cloud storage.
- Observe whether the database type changes to cloud.
- Disconnect network / switch to Airplane Mode.
- Attempt to open the database.
- Attempt CRUD: add / edit / move / delete an entry.
Expected
- Syncing does not turn a local DB into a cloud-only database.
- Read/write actions work directly on the local copy.
- Cloud sync only runs during automatic intervals or manual trigger.
- When offline, app uses the local copy immediately without timeout.
Result
Status: ❌ FAIL
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Comments:
RC9-N13AC-817Sev-2⏭️ SKIP
Settings: Separate App-level and Database-level Settings in UI and Tablet Navigation
Setup needed: A device with at least one open database.
RC9 status: OPEN (new #13) — Settings menu mixes database-level and app-level settings into a single flat list, causing confusion about scope. Tablet navigation does not clearly differentiate global vs database-specific settings.
Steps
- Open Settings.
- Observe whether App-level settings (Autofill & passkeys, Databases & sync, General, Support) are separated from Database-level settings (Security, Backup copies).
- On tablet: tap the left rail Settings button; verify only App-level settings open.
- On tablet: open a database; verify a dedicated Settings / Database Properties button exists in the top bar for that DB.
Expected
- Settings are clearly separated into App-level and Database-level.
- Tablet left rail Settings opens only App-level settings.
- An open database view provides an entry point to that database's settings.
- UI clearly communicates scope of each setting.
Result
Status: ⏭️ SKIP
Comments:
Part 2 — RC9 Blocked Re-Test
These 2 items were BLOCKED in the RC9 QA Report (2026-10-05, section 3g) because MDM was disabled on the test devices. Re-test on RC10 with an MDM profile that bans export / cloud / autofill / clipboard.
RC9-B1SEC-2Sev-1🚫 BLOCKED
MDM bans (export, cloud, autofill, clipboard) enforced at the sink
Setup needed: A device with an MDM profile that bans export / cloud / autofill / clipboard.
RC9 status: BLOCKED — RC9: "MDM is disabled."
Steps
- With the MDM profile active, try to export a database / entry.
- Try to use cloud sync (WebDAV / Google Drive / HiDrive).
- Try autofill on a login page.
- Try to copy a password to the clipboard.
- Verify each is blocked at the sink (not just hidden in the UI).
Expected
- Export blocked at the file-write sink.
- Cloud blocked at the network sink.
- Autofill blocked at the fill sink.
- Clipboard blocked at the clipboard-write sink.
- No bypass via direct intent / share / external app.
Result
Status: 🚫 BLOCKED
Environment / blocker info: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Comments:
RC9-B2SEC-3Sev-1⏭️ SKIP
MDM bans enforced in the autofill / passkey process (from round 5)
Setup needed: A device with an MDM profile that bans autofill / clipboard.
RC9 status: BLOCKED — RC9: "MDM is disabled."
Steps
- With the MDM profile active, trigger autofill in a browser and in an app.
- Trigger a passkey registration / sign-in.
- Verify the bans are enforced inside those processes.
- Try to bypass via the autofill UI or passkey UI.
Expected
- Autofill process enforces the MDM bans.
- Passkey process enforces the MDM bans.
- No bypass from the independent process.
Result
Status: ⏭️ SKIP
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Comments:
Part 3 — RC9 Skipped Re-Test
This 1 item was SKIPPED in the RC9 QA Report (2026-10-05, section 3h) because it was not ready for testing. Re-test on RC10.
RC9-S1AC-766Sev-2⏭️ SKIP
Unable to access Server DB Settings on Tablet (Left rail Settings opens Local/Cloud DB settings instead)
Setup needed: Android tablet (or tablet/expanded layout mode) with an Enterprise Server DB session.
RC9 status: SKIP — RC9: "This is not ready for test."
Steps
- Open Password Depot on an Android tablet, or use tablet/expanded layout mode.
- Connect and log into an Enterprise Server database.
- Tap the Settings icon/item in the left navigation rail.
- Check whether Server DB Settings opens (vs Local/Cloud DB settings).
- Close or return from Settings; confirm the active Server DB session is preserved.
Expected
- The navigation rail Settings opens the active Server DB settings when connected to an Enterprise Server DB, OR a dedicated Settings / Database Properties (⚙️) icon is available in the Server DB top bar/header (matching the phone mode implementation from AC-746).
- Closing or returning from Settings keeps the user inside the active Server DB session.
Result
Status: ⏭️ SKIP
Comments:
Part 4 — RC8 NEW BUGS Regression (1)
This 1 RC8 New Bug was verified PASS in RC9 (RC9 QA Report 2026-10-05, section 3b). Confirm no regression on RC10.
RC8-N2AC-767Sev-2✅ PASS
[Server DB] Support adding and editing additional URLs for entries
Setup needed: Enterprise Server DB; an entry with URL field; local DB or Windows client for comparison.
RC9 status: PASS — RC9: Verified PASS.
Steps
- Open an entry in the Server DB entry editor.
- Try to add an additional URL.
- Try to edit an additional URL.
- Try to delete an additional URL.
- Compare with the local DB entry editor and the Windows client.
Expected
- Users can add/edit/delete additional URLs for Server DB entries.
- The URL section supports a list mechanism and a "+" option.
Result
Status: ✅ PASS
Comments:
Part 5 — RC5 NEW BUGS Regression (10)
These 10 RC5 New Bugs were verified PASS in RC9 (RC9 QA Report 2026-10-05, section 3c). Confirm no regression on RC10.
RC5-N2AC-717Sev-2✅ PASS
Switching to standard user offline DB still prompts for SSO login after saving SSO offline DB
Setup needed: A device with an SSO offline DB already saved; a standard-user offline DB available.
RC9 status: PASS
Steps
- Sign in with SSO and save an SSO offline DB.
- Sign out.
- Attempt to open a standard-user offline DB.
- Observe the login prompt (SSO vs standard).
- Try switching back to standard-user login.
Expected
- The client offers standard user login for the standard-user offline DB.
- No SSO prompt is forced.
Result
Status: ✅ PASS
Comments:
RC5-N3AC-732Sev-2✅ PASS
Server certificate confirmation prompt reappears when clicking "Load databases" in "Save offline copy" after already trusting the certificate
Setup needed: Enterprise Server 20; certificate previously trusted.
RC9 status: PASS
Steps
- Sign in to the server and trust the certificate.
- Start "Save offline copy".
- Tap "Load databases".
- Observe whether the certificate confirmation prompt reappears.
Expected
- Certificate is remembered; no repeated confirmation prompt.
Result
Status: ✅ PASS
Comments:
RC5-N4AC-679Sev-2✅ PASS
Home screen: Keep "Another way in" section expanded by default when databases exist
Setup needed: A device with at least one local DB.
RC9 status: PASS
Steps
- Expand the "Another way in" section on the Home screen.
- Create a new local DB.
- Return to the Home screen.
- Check whether the section is still expanded.
Expected
- "Another way in" stays expanded by default when databases exist.
Result
Status: ✅ PASS
Comments:
RC5-N5AC-733Sev-2✅ PASS
[UX] Expand markdown toolbar items in full-screen comment editor instead of keeping them in the overflow dropdown
Setup needed: An entry with a comment field on a device with enough horizontal space (tablet recommended).
RC9 status: PASS
Steps
- Open the comment editor.
- Switch to full-screen mode.
- Observe the markdown/formatting toolbar.
- Compare with the compact/inline view.
Expected
- Full-screen toolbar exposes more (or all) formatting items directly.
Result
Status: ✅ PASS
Comments:
RC5-N6AC-734Sev-2✅ PASS
Align "Conditional access" tab in Entry editor with Windows client (UI items, warning levels & access triggers)
Setup needed: Entry editor on Android; Windows client for reference; Server 20 with ES-1002 for server path.
RC9 status: PASS
Steps
- Open the Entry editor on Android → Conditional access tab.
- Check the severity radio options (Informational / Major / Critical).
- Select Critical; verify the Verification text input becomes active.
- Test on a Local DB (.pswe).
- Test on an offline copy.
- Test on a Server DB via REST v2 ES-1002.
Expected
- Three severity radio options present and match Windows.
- Verification text input active only when Critical is selected.
Result
Status: ✅ PASS
Comments:
RC5-N9AC-738Sev-2✅ PASS
[Support Data] Copy button fails to copy logs under "From the autofill process"
Setup needed: A device with autofill logs present.
RC9 status: PASS
Steps
- Lock the app → tap "Support data…" on the unlock screen.
- Locate the "From the autofill process" section.
- Tap "Copy".
- Paste into a text editor and inspect the content.
Expected
- The full Support Data (including "From the autofill process") is copied.
Result
Status: ✅ PASS
Comments:
RC5-N10AC-739Sev-2✅ PASS
[Support Data] Include app version, Android OS version, and default browser version in support data logs
Setup needed: Any device.
RC9 status: PASS
Steps
- Lock the app → tap "Support data…" on the unlock screen.
- Inspect the content.
- Check for: app version, Android OS version, default browser version.
- Tap "Copy" and paste into a text editor to confirm they are present.
Expected
- App version, Android OS version, and default browser version appear in Support Data and in copied content.
Result
Status: ✅ PASS
Comments:
RC5-N11AC-698Sev-2✅ PASS
[Tablet][Enterprise] Server DB does not use two-pane (master-detail) layout unlike Local DB
Setup needed: Android tablet (or large-screen device / emulator); both a Local DB and an Enterprise Server DB available.
RC9 status: PASS
Steps
- Launch Password Depot on an Android tablet.
- Open a Local DB (Entries tab) and tap any entry. Observe: two-pane split view.
- Switch to the Enterprise tab and open an Enterprise Server DB.
- Tap any entry from the list in Server DB.
- Observe the layout.
- Rotate the device; observe whether the layout survives.
Expected
- Server DB uses the same two-pane (master-detail) layout as Local DB.
Result
Status: ✅ PASS
Comments:
RC5-N12AC-704Sev-2✅ PASS
[Autofill][Android 14 Tablet] "Setup Autofill" banner remains visible after enabling autofill service and credential provider
Setup needed: Android 14 (API 34) tablet (e.g. T33-F11). Compare with Android 15+ (API 35, e.g. Galaxy S22).
RC9 status: PASS
Steps
- Install a clean build on the Android 14 device (or clear app cache/data).
- Launch the app and log in / open a DB.
- Observe the "Setup Autofill" prompt/banner at the top of the entry list.
- Tap the "Setup Autofill" banner → system configuration screen.
- In Android System Settings: enable Password Depot under Passwords, passkeys & autofill; ensure it is toggled/selected under Additional providers / Credential Manager.
- Switch back / navigate back to Password Depot.
- Observe the banner.
- Repeat on Android 15+ for comparison.
Expected
- App detects that autofill service is enabled upon onResume.
- "Setup Autofill" banner automatically disappears.
Result
Status: ✅ PASS
Comments:
RC5-N13AC-707Sev-2✅ PASS
[Security/Settings] Enable lowercase, uppercase, and numbers by default in Master Password Policy
Setup needed: Clean install (or cleared app data), no enterprise-managed settings override.
RC9 status: PASS
Steps
- Fresh install / clear app data.
- Open Settings → Master password policy.
- Observe the default values.
- Create a new database; set a master password that violates the new defaults.
- Try to change the master password with the same weak password.
Expected
- Min length = 8; Lowercase = ON; Uppercase = ON; Numbers = ON; Special characters = OFF.
Result
Status: ✅ PASS
Comments:
Part 6 — RC10 Smoke: Google Play Readiness
RC10 is the build that will go to Google Play. This is the smoke pass that must be green before submission. RC9 passed all 7; RC10 must confirm no regression.
RC-1Sev-0✅ PASS
Release build identity and Play Store readiness
Setup needed: A device with Google Play installed.
What to test: Confirm build identity, target API 36, release configuration.
RC9 status: PASS
Steps
- Settings → Version; confirm "20.0.0 RC10 (2010)".
- App info; confirm targetSdkVersion Android 16 (API 36).
- Not debuggable; no debug surface.
- Screenshots/recording blocked.
- Package name matches Play listing.
Expected
- Version line exact; API 36; not debuggable; screenshots blocked; package name correct.
Result
Status: ✅ PASS
Comments:
RC-2Sev-0✅ PASS
First launch on a clean device (no test data)
What to test: Empty start screen, first DB creation, first entry creation end to end.
RC9 status: PASS
Steps
- Uninstall previous build.
- Install RC10 from internal test track.
- Open; confirm empty start screen.
- Create DB; add entry; lock/unlock.
- Force-close and relaunch; confirm locked.
Expected
- Empty start; DB/entry creation works; force-close restarts locked.
Result
Status: ✅ PASS
Comments:
RC-4Sev-0✅ PASS
Privacy policy and data safety
What to test: Privacy policy link present, reachable, matching Data Safety declaration.
RC9 status: PASS
Steps
- Settings → About/Legal; confirm privacy policy link.
- Tap; confirm opens in browser.
- Confirm Data Safety declaration matches app.
Expected
- Link present and reachable; content matches; declaration accurate.
Result
Status: ✅ PASS
Comments:
RC-5Sev-1✅ PASS
Android 16 (API 36) edge-to-edge and 3-button navigation
Setup needed: Android 15/16 device with 3-button navigation.
What to test: Edge-to-edge drawing on Android 15/16 phones with 3-button navigation.
RC9 status: PASS
Steps
- Open app on Android 15/16 with 3-button navigation.
- Check status bar, navigation bar, keyboard.
- Open autofill window and passkey dialogs.
- Rotate.
Expected
- Edge-to-edge correct; no content hidden.
Result
Status: ✅ PASS
Comments:
RC-6Sev-1✅ PASS
All 27 languages shipped in RC10
What to test: All 27 languages listed and switching works.
RC9 status: PASS
Steps
- Settings → App language.
- Confirm 27 languages.
- Switch to three; confirm UI changes.
- Switch back to English.
Expected
- 27 languages listed; switching works without restart.
Result
Status: ✅ PASS
Comments:
RC-7Sev-1✅ PASS
Upgrade from RC9 to RC10 with data kept
Setup needed: Device with RC9 installed and a populated DB.
What to test: Update from RC9 without losing data.
RC9 status: PASS
Steps
- Install RC9; create DB with entries + second-password entry.
- Update to RC10.
- Confirm DB still there and unlocks.
- Confirm entries/second-password/settings intact.
Expected
- Update installs over RC9; data kept.
Result
Status: ✅ PASS
Comments:
RC-8Sev-0✅ PASS
Crash-free cold start and warm start
What to test: Cold/warm start and autofill reconnect do not crash. RC9 passed; RC10 must confirm.
RC9 status: PASS
Steps
- Cold start: force-stop, then open.
- Warm start: background then foreground.
- Reboot device; open again.
- Autofill reconnect: expire server DB session, trigger autofill, tap "Use a local database instead".
- Watch for crash/ANR/freeze.
Expected
- Cold start OK; warm start clean; reboot OK; autofill reconnect no crash.
Result
Status: ✅ PASS
Comments:
Part 7 — Security & MDM
All PASS in RC9 (except SEC-2/SEC-3 which were BLOCKED and are now in Part 2). Confirm no regression on RC10.
SEC-1Sev-1✅ PASS
Migration path uses the same wrong-password throttle as the unlock screen
RC9 status: PASS
Steps
- Start the migration / import from previous app flow.
- Enter the wrong password several times.
- Observe whether the same throttle as the unlock screen kicks in.
- Enter the correct password after the throttle.
Expected
- Wrong-password throttle applies to the migration path.
- Clear message shown when throttled.
Result
Status: ✅ PASS
Comments:
SEC-4Sev-1✅ PASS
Tablet: revealing a password no longer wanders to the next entry when selection changes
Setup needed: A tablet / foldable with the two-pane layout.
RC9 status: PASS
Steps
- Open entry A in the detail pane.
- Reveal the password for A.
- Select entry B in the list.
- Verify B does not show A’s plaintext.
- Select back A; verify A’s reveal state is correct.
- Rotate / search / filter / scroll; verify no plaintext leaks.
- Lock and unlock; verify reveal state is reset.
Expected
- Revealed password is bound to its entry.
- Changing selection does not carry plaintext to another entry.
Result
Status: ✅ PASS
Comments:
Part 8 — RC1 Reported Bugs Regression (10 PASS)
These RC1 Reported Bugs passed in RC9. AC-624 (Edge autofill) was already resolved in RC9 Part 0. Confirm no regression on RC10.
REV-N1AC-620Sev-2✅ PASS
Autofill: Modifying username after autofill and logging in creates a new entry instead of updating existing entry
RC9 status: PASS
Steps
- Autofill username/password in Chrome.
- Change the username in the form.
- Log in; tap Update when prompted.
- Check: existing entry updated, no new entry created.
Expected
- Existing entry is updated; no new entry is created.
Result
Status: ✅ PASS
Comments:
REV-N2AC-623Sev-2✅ PASS
Recycle Bin: Add button/option to empty or clean recycle bin
RC9 status: PASS
Steps
- Open the recycle bin.
- Look for an "Empty recycle bin" action.
Expected
- A button/menu option empties the whole recycle bin at once.
Result
Status: ✅ PASS
Comments:
REV-N4AC-625Sev-2✅ PASS
Server DB: TOTP field/code is not displayed in entry details view on Android client
RC9 status: PASS
Steps
- Sign in to Enterprise Server 20.
- Open an entry with a TOTP secret.
- Check the entry details view.
Expected
- TOTP field and current code displayed.
Result
Status: ✅ PASS
Comments:
REV-N5AC-626Sev-2✅ PASS
Entry Details: Importance set to "High" is incorrectly displayed as "Low" on Android client
RC9 status: PASS
Steps
- Create/update entry with Importance = High on Windows.
- Open same entry on Android.
- Check the Importance badge.
Expected
- Importance badge reads "High".
Result
Status: ✅ PASS
Comments:
REV-N6AC-627Sev-2✅ PASS
Entry: Warning message configured on Windows client does not pop up when accessing the entry on Android
RC9 status: PASS
Steps
- Configure warning message on Windows for an entry.
- Sync/open DB on Android.
- Open that entry.
Expected
- Warning dialog appears with configured text before details are shown.
Result
Status: ✅ PASS
Comments:
REV-N7AC-628Sev-2✅ PASS
Server DB: Redundant "Expires" field displayed in DETAILS block for Credit Card entries created via Windows Client in ES DB
RC9 status: PASS
Steps
- Create Credit Card entry on Windows in ES DB.
- Open on Android.
- Check DETAILS for redundant Expires.
Expected
- No redundant/empty Expires field.
Result
Status: ✅ PASS
Comments:
REV-N8AC-629Sev-2✅ PASS
Unify entry field/item names across new clients with Windows client
RC9 status: PASS
Steps
- Open a few entry types on Android.
- Compare labels with Windows client.
Expected
- Field/item names match the Windows client wording.
Result
Status: ✅ PASS
Comments:
REV-C1AC-440Sev-2✅ PASS
Android Client becomes slow and laggy when database contains 20,000+ entries
RC9 status: PASS
Steps
- Open a DB with 20,000+ entries.
- Scroll the entry list.
- Search by title.
Expected
Result
Status: ✅ PASS
Comments:
REV-C2AC-430Sev-2✅ PASS
SSPI login mode - User Logon Name Format settings do not match expected behavior for Simple, Domain\sAMAccountName, and UPN modes
RC9 status: PASS
Steps
- Open Enterprise login.
- Try Simple, DOMAIN\user, user@company.com.
- Sign in with each against Server 20 + AD.
Expected
- All three formats behave as expected.
Result
Status: ✅ PASS
Comments:
REV-C3AC-333Sev-2✅ PASS
Better to open a numeric keyboard when input a Service phone field
RC9 status: PASS
Steps
- Open an entry with a Service phone field.
- Focus that field.
Expected
- A numeric keyboard opens.
Result
Status: ✅ PASS
Comments:
Part 9 — Beta21 / RC1 Regression (R18-1 – R18-7)
These bugs were reported in earlier rounds. All PASS in RC9. Re-test on RC10.
R18-1AC-604Sev-0✅ PASS
Key file of the old app — now visible in every key-file prompt
Setup needed: A real 19.x installation with a key-file database.
RC9 status: PASS
Steps
- Install 19.x; create/protect DB with key file.
- Update to RC10; open takeover flow.
- Unlock screen → "Choose key file…".
- Verify old app key files listed.
- Pick correct one; unlock.
- Repeat in autofill window and passkey dialog.
- Change master password and restore.
Expected
- Old key files listed in every key-file prompt.
Result
Status: ✅ PASS
Comments:
R18-2AC-605Sev-3✅ PASS
Key-file wording: "Protected with" vs "Additionally protected with"
RC9 status: PASS
Steps
- Open key-file-only DB; check wording.
- Open password+key-file DB; check wording in same three places.
Expected
- Correct wording in both cases.
Result
Status: ✅ PASS
Comments:
R18-3AC-606Sev-3✅ PASS
Names after the takeover
Setup needed: A real 19.x migration.
RC9 status: PASS
Steps
- Migrate DB from 19.x with long path and extension.
- Check name in DB list.
- Create backup copy; check name.
- Open DB; check header.
Expected
- DB name is file name without folder/extension.
Result
Status: ✅ PASS
Comments:
R18-4AC-607Sev-3✅ PASS
Takeover report lists skipped settings by name
Setup needed: A real 19.x installation with an invalid setting.
RC9 status: PASS
Steps
- Migrate from 19.x with at least one invalid setting.
- Open takeover report.
Expected
- Skipped settings listed by name.
Result
Status: ✅ PASS
Comments:
R18-5AC-609Sev-2✅ PASS
WebDAV address with "#" gets its own message
Setup needed: HiDrive account (or similar WebDAV address with "#").
RC9 status: PASS
Steps
- Open "Open from cloud…" / "Storage location & sync".
- Paste browser address of HiDrive web interface (contains "#").
- Observe message.
- After entering username, verify "database.pswe" is NOT stripped.
Expected
- Specific message says what to enter instead.
Result
Status: ✅ PASS
Comments:
R18-6AC-610Sev-3✅ PASS
Autofill hint names the app’s auto-lock value
RC9 status: PASS
Steps
- Set app auto-lock shorter than reuse window.
- Settings → Autofill & passkeys; find "keep unlocked for …" hint.
Expected
- Hint names auto-lock and shows its value.
Result
Status: ✅ PASS
Comments:
R18-7AC-537 / AC-608Sev-1✅ PASS
Enterprise Server: one-time codes and 2FA against Server 20
Setup needed: Enterprise Server 20 (only).
RC9 status: PASS
Steps
- Sign in to Enterprise Server 20.
- Trigger autofill on a site matching a server entry with one-time code.
- Verify username, password and current one-time code filled.
- Trigger 2FA failure; observe exact reason.
Expected
- Autofill fills username/password/one-time code; 2FA failures report exact reason.
Result
Status: ✅ PASS
Comments:
Part 10 — Core Pass: A1–A10 (Every Tester, Every Device)
Estimated time: 45–60 minutes. Run on every device you test. All PASS in RC9; confirm no regression on RC10.
A1✅ PASS
First Launch & Database Creation
RC9 status: PASS
Steps
- Fresh install (or update): open app.
- Create DB with name and test master password.
- Confirm empty entry list.
- Relaunch.
- Enter master password; confirm unlock.
- Enter wrong master password.
Expected
- Empty list; after relaunch locked; correct password unlocks; wrong password clear error.
Result
Status: ✅ PASS
Comments:
A2✅ PASS
Entries of Several Types
RC9 status: PASS
Steps
- Create password entry, credit card (PIN/CVV), identity, information, protected custom field.
- While typing secret fields, check keyboard.
- Open detail view for each.
- Edit each and re-save.
- Windows interop: create encrypted file on Windows, verify visible on Android.
Expected
- Secret fields use password keyboard; detail view readable; nothing lost after edit; encrypted file visible on Android.
Result
Status: ✅ PASS
Comments:
A3✅ PASS
Folders, Search, Trash
RC9 status: PASS
Steps
- Create two folders.
- Move entries.
- Search by title, username, URL.
- Delete entry (move to trash).
- Restore from recycle bin.
Expected
- All operations complete; restored entry in original location.
Result
Status: ✅ PASS
Comments:
A4✅ PASS
Locking
RC9 status: PASS
Steps
- Background and return quickly.
- Stay away past auto-lock.
- Force-close from Recents.
- Relaunch.
Expected
- Quick background stays open; after timeout locked; after force-close next start locked.
Result
Status: ✅ PASS
Comments:
A5✅ PASS
Biometric Unlock + Invalidation
RC9 status: PASS
Steps
- Enable Settings → Security → Biometric unlock.
- Lock DB.
- Unlock with fingerprint/face.
- Enroll additional fingerprint in Android settings.
- Return to app.
Expected
- Biometric unlock works; after new fingerprint app refuses biometrics with explanation; can re-enable.
Result
Status: ✅ PASS
Comments:
A6✅ PASS
Clipboard
RC9 status: PASS
Steps
- Copy password from detail view.
- Check countdown notification.
- Paste in another app.
- Wait 30s; attempt paste again.
- Try "Clear now".
Expected
- Countdown appears; paste within 30s; after 30s no paste; "Clear now" immediate.
Result
Status: ✅ PASS
Comments:
A7✅ PASS
Autofill in Your Daily Browser
Note: Chrome 131+ extra step: Chrome → Settings → Autofill services → "Autofill using another service" → restart Chrome.
RC9 status: PASS
Steps
- Enable Settings → Autofill service.
- Settings → Autofill test; confirm suggestion.
- Navigate to test login page.
- Verify suggestion.
- Fill with Password Depot.
- Log in with new credential typed manually; confirm save/update prompt.
- Negative check: look-alike domain; entry NOT offered.
Expected
- Suggestion on matching domain; save/update works; no suggestion for non-matching.
Result
Status: ✅ PASS
Comments:
A8✅ PASS
Autofill in One App
RC9 status: PASS
Steps
- Open any app with login screen (test account).
- Trigger autofill.
Expected
- Autofill works or cleanly offers nothing — no crash, no wrong entry.
Result
Status: ✅ PASS
Comments:
A9✅ PASS
Appearance, Language, Rotation, Tablet
RC9 status: PASS
Steps
- Switch appearance dark → light → system.
- Switch app language DE ↔ EN.
- Rotate device while unlocked.
- (Tablet/foldable) Verify two-pane layout.
Expected
- Switches work without restart; rotation preserves state; two-pane correct on tablets.
Result
Status: ✅ PASS
Comments:
A10✅ PASS
Stability & Error Visibility
What to test: Any crash, freeze, or silently swallowed error is a top report.
RC9 status: PASS
Steps
- If any occur, open Support data immediately.
- Copy version line and events.
- File Jira Bug Sev-0 with support data.
Expected
- No crashes, freezes, or silently swallowed errors.
Result
Status: ✅ PASS
Comments:
Part 11 — Focus Blocks C1–C11
All PASS in RC9; confirm no regression on RC10.
C1🔄 IN PROGRESS
TOTP
Setup needed: A test account with 2FA/TOTP and a reference authenticator app.
RC9 status: PASS
Steps
- Add TOTP secret via entry editor.
- Use "Scan QR code" (camera/photo).
- Compare 6-digit code with reference authenticator for ≥3 periods.
- With autofill: confirm code offered only into one-time-code field.
Expected
- Codes match for ≥3 periods; code offered only into OTP fields.
Result
Status: 🔄 IN PROGRESS
Comments:
C2✅ PASS
Passkeys (Android 14+)
Setup needed: Android 14+, screen lock enabled. Test site: https://webauthn.io
RC9 status: PASS
Steps
- Settings → Passkey provider → Password Depot; verify "Enabled".
- Register a new passkey on webauthn.io.
- Sign in with the passkey.
- Move passkey entry to trash.
- Attempt sign-in → expect "No matching passkey".
- Restore passkey entry.
- Attempt sign-in again → works.
Expected
- All steps behave as described.
Result
Status: ✅ PASS
Comments:
C3✅ PASS
WebDAV Sync
Setup needed: A real Nextcloud and/or Apache WebDAV server over HTTPS.
RC9 status: PASS
Steps
- Link WebDAV server.
- Initial DB upload.
- Edit entry on Android; sync; verify on Windows.
- Edit same entry on both simultaneously.
- Sync from Android.
Expected
- Initial upload succeeds; concurrent edit → conflicted copy on Android.
Result
Status: ✅ PASS
Comments:
C4✅ PASS
Windows Interop
Setup needed: Windows Password Depot 19 and same DB accessible on both.
RC9 status: PASS
Steps
- Open same .pswe alternately in Windows PD 19 and Android.
- Verify umlauts/emoji, folders, attachments, TAN lists, entry history, custom icons, second-password entry survive both directions.
- Set expiry date on Android; open in Windows; confirm date preserved.
Expected
- All content survives both directions unchanged.
Result
Status: ✅ PASS
Comments:
C5✅ PASS
Attachments
RC9 status: PASS
Steps
- Attach photo (few MB); reopen and export.
- Attach PDF (few MB); reopen and export.
- Attempt to attach file over 25 MB.
Expected
- Photo/PDF attach, export, open correctly; >25 MB refused with clear message, no crash.
Result
Status: ✅ PASS
Comments:
C6✅ PASS
Multi-Database & Master Password Change
What to test: App copy of every DB lives in app private storage; "on this device" DB has no external file.
RC9 status: PASS
Steps
- Create second DB; switch between both.
- Export copy; open via "Open database file…".
- Remove THAT entry from app — file in Downloads must still exist — and open again.
- Change master password of test DB.
- Attempt unlock with old password.
Expected
- Switching works; "Remove from app" does not delete external file; old password rejected.
Result
Status: ✅ PASS
Comments:
C7✅ PASS
Backup & Restore
RC9 status: PASS
Steps
- Databases & sync → Backup copies; create backup.
- Make changes.
- Restore earlier backup.
- Wrong password during restore; check throttle and message.
- Correct password; confirm restore.
- Attempt restore of corrupted backup.
Expected
- Correct password restores; current state saved before restore; wrong password throttle + message; corrupted backup refused, active DB untouched.
Result
Status: ✅ PASS
Comments:
C8✅ PASS
Enterprise Thin Client
Setup needed: Office test server (Enterprise Server 20).
RC9 status: PASS
Steps
- App → "Enterprise server…".
- Enter address/port; log in.
- First connect: verify TLS fingerprint dialog.
- Browse and search entries.
- Edit entry and save.
Expected
- TLS fingerprint dialog first connect; login succeeds; browse/search/edit work.
Result
Status: ✅ PASS
Comments:
C9✅ PASS
Enterprise Offline Copy
Setup needed: Enterprise Server 20, TCP port 25020, DB with offline right granted.
RC9 status: PASS
Steps
- Sign in; tap "Save offline copy…".
- Enter server password.
- Tap "Load databases" — confirm TLS fingerprint once.
- Pick DB; confirm copy saved.
- Sign out; tap "Open offline copy".
- Create/edit entry offline; note waiting-changes counter.
- Settings → Sync… → "Send changes to the server".
Expected
- All steps behave as described.
Result
Status: ✅ PASS
Comments:
C10✅ PASS
Enterprise Single Sign-On (OpenID Connect / Entra ID)
Setup needed: Enterprise Server 20 with configured OIDC or Entra ID provider.
RC9 status: PASS
Steps
- Choose "Single sign-on (OpenID Connect / Entra ID)"; tap "Connect".
- Complete sign-in in browser.
- Sign out; use "Sign in with a different account".
- Start sign-in and cancel in browser.
- Sign in with account server does not know.
Expected
- All scenarios behave as described.
Result
Status: ✅ PASS
Comments:
C11✅ PASS
Hand-Over of Previous-App Offline Changes
Setup needed: Enterprise Server 20, TCP port 25020.
RC9 status: PASS
Steps
- Start with previous Password Depot for Android installed and Enterprise DB with unsent offline changes.
- Update to RC10; open "Import from previous app".
- Verify report names number of unsent changes.
- Tap "Send to the server…".
- Confirm note disappears and changes on server.
Expected
- All steps behave as described.
Result
Status: ✅ PASS
Comments:
5 · Device Matrix Contribution
| Dimension | Variant | Covered | Notes |
|---|
| Keyboard | Gboard | ✅ | |
| Keyboard | Samsung Keyboard | ✅ | |
| Keyboard | SwiftKey | ✅ | |
| Browser | Chrome | ✅ | |
| Browser | Edge | ✅ | |
| Browser | Firefox | ✅ | |
| Browser | Samsung Internet | ❌ | |
| Autofill style | Android 11+ inline chips | ✅ | |
| Autofill style | Android ≤13 dropdown | ✅ | |
| Clipboard | Samsung clipboard behavior | ✅ | |
| Clipboard | Pixel clipboard behavior | ✅ | |
| Clipboard | Xiaomi clipboard behavior | n/a | |
| Biometrics | Fingerprint | ✅ | |
| Biometrics | Face unlock | ✅ | |
| Biometrics | Both enrolled | ✅ | |
| OEM quirks | Xiaomi/HyperOS battery saver — auto-lock reliable? | n/a | |
| OEM quirks | Samsung battery saver — session killed mid-edit? | ✅ | |
| Form factor | Phone | ✅ | |
| Form factor | Tablet (≥ 600 dp) | ✅ | |
| Form factor | Foldable | n/a | |
| Storage | FTPS / FTPES | ✅ | |
| Storage | HiDrive | ✅ | |
| Migration | 19.x migration with key-file database | ✅ | |
| RC10 Smoke | Google Play internal test track install | ✅ | |
6 · Reporting Reference
| Jira Project | Android Client (AC) |
|---|
| Affects Version | 20.0.0 |
|---|
| Build line | 20.0.0 RC10 (2010) |
|---|
| Release | RC10 · Google Play submission pending |
|---|
| Severity 0 | crash · data loss · lock-out |
|---|
| Severity 1 | feature wrong or unusable |
|---|
| Severity 2 | wrong, has a workaround |
|---|
| Severity 3 | visual / text |
|---|
Support data: lock the app → tap "Support data…" on the unlock screen.