Password Depot for Android — RC4 QA Test Report
Build 20.0.0 RC4 · Release Candidate 4 · Regression of 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · Generated 9/28/2026, 6:59:55 PM
1 · Environment
| Device / Android | Galaxy S22 |
|---|
| Keyboard | Samsung Keyboard 5.9.12 |
|---|
| Browser(s) | Chrome 152, Edge 152, Firefox 155 |
|---|
| Build line | 20.0.0 RC4 (2000) |
|---|
| Tester | Sheva Ma |
|---|
| Date started | 2026-Sep-28 |
|---|
2 · Summary
| Block | Total | ✅ Pass/Fixed | ❌ Fail | 🚫 Blocked | ⏭️ Skip | 🔄 In Progress | ⬜ Pending |
|---|
| Part 0a — Reported Bugs Re-Verification (from RC1 report) | 11 | 11 | 0 | 0 | 0 | 0 | 0 |
| Part 0b — RC4 Smoke: Google Play Readiness | 7 | 7 | 0 | 0 | 0 | 0 | 0 |
| Part 0c — RC1 Regression: Beta21 / RC1 Bug Fixes | 7 | 6 | 0 | 0 | 0 | 1 | 0 |
| Part 1 — Core Pass: A1–A10 (Every Tester, Every Device) | 10 | 10 | 0 | 0 | 0 | 0 | 0 |
| Part 3 — Focus Blocks C1–C11 | 11 | 11 | 0 | 0 | 0 | 0 | 0 |
| Part 4 — RC1 New Bugs Re-Test (AC-638, AC-639, AC-640, AC-646) | 4 | 3 | 1 | 0 | 0 | 0 | 0 |
| Part 5 — RC1 Closed Bugs Regression (14) | 14 | 14 | 0 | 0 | 0 | 0 | 0 |
| Total | 64 | 62 | 1 | 0 | 0 | 1 | 0 |
| Items tested / total | 63 / 64 |
|---|
| Pass rate (of decided items) | 98% |
|---|
| Failures | 1 |
|---|
| Blocked items | 0 |
|---|
| Reported bugs re-verified: fixed | 11 / 11 |
|---|
| Reported bugs re-verified: still broken | 0 / 11 |
|---|
| New bugs discovered (manual entry) | 2 |
|---|
| Closed bugs (verified fixed this round) | 11 |
|---|
3a · Reported Bugs Re-Verification (from RC1 report) (11)
These are the bugs from the RC1 report. Each entry shows the original report details and the RC4 re-verification verdict.
New Bugs from RC1 report (8)
REV-N1AC-620Sev-2RC1: FIXEDRC4: ✅ FIXEDAutofill: Modifying username after autofill and logging in creates a new entry instead of updating existing entry
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #1
Original device: Galaxy S22, Android 15
Original note: Problem Summary: After autofilling username and password in the Chrome browser, if the user changes the username and logs in, Password Depot prompts to update the entry. Clicking Update creates a new entry instead of updating the existing one.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N2AC-623Sev-2RC1: FIXEDRC4: ✅ FIXEDRecycle Bin: Add button/option to empty or clean recycle bin
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #2
Original device: NA
Original note: Currently in the Android client Recycle Bin view, there is no option or button to empty/clean the entire recycle bin. Users have to handle items individually.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N3AC-624Sev-2RC1: FIXEDRC4: ✅ FIXEDAutofill: Autofill in Edge browser fails to detect target URL (unknown target)
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #3
Original device: Samsung Galaxy S22
Original note: Autofill in Microsoft Edge on Android does not detect the target website URL. Users see an "unknown target" message, and the matching saved password entry is not automatically suggested.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N4AC-625Sev-2RC1: FIXEDRC4: ✅ FIXEDServer DB: TOTP field/code is not displayed in entry details view on Android client
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #4
Original device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Original note: When viewing a password entry stored in an Enterprise Server database on the Android client, the TOTP field and generated one-time code do not display in the entry details view, even though the TOTP secret is configured and working properly on the Windows client.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N5AC-626Sev-2RC1: FIXEDRC4: ✅ FIXEDEntry Details: Importance set to "High" is incorrectly displayed as "Low" on Android client
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #5
Original device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Original note: When an entry is created or updated with its Importance level set to "High" (via Windows client or Server DB), the Android client incorrectly displays the Importance badge as "Low" under the DETAILS section.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N6AC-627Sev-2RC1: BLOCKEDRC4: ✅ FIXEDEntry: Warning message configured on Windows client does not pop up when accessing the entry on Android
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #6
Original device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Original note: When accessing an entry with a configured warning message, a warning prompt/dialog should pop up displaying the warning text, requiring user confirmation before displaying details or copying credentials (consistent with the Windows client behavior).
RC1 note: RC1: Need to wait ES-1002 ready for testing.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N7AC-628Sev-2RC1: FIXEDRC4: ✅ FIXEDServer DB: Redundant "Expires" field displayed in DETAILS block for Credit Card entries created via Windows Client in ES DB
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #7
Original device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Original note: The DETAILS block should not display a redundant/empty Expires field for Credit Card entries.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N8AC-629Sev-2RC1: FIXEDRC4: ✅ FIXEDUnify entry field/item names across new clients with Windows client
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #8
Original device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Original note: Feature request: Unify entry field/item names across new clients with Windows client.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
Closed Bugs from RC1 report (3)
REV-C1AC-440Sev-2RC1: FIXEDRC4: ✅ FIXEDAndroid Client becomes slow and laggy when database contains 20,000+ entries
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · Closed bug #1
Original device: — not provided — · Originally fixed in: 20.0.0-beta22 (1952)
Original note: Verified closed
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-C2AC-430Sev-2RC1: FIXEDRC4: ✅ FIXEDSSPI login mode - User Logon Name Format settings do not match expected behavior for Simple, Domain\sAMAccountName, and UPN modes
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · Closed bug #2
Original device: — not provided — · Originally fixed in: 20.0.0-beta22 (1952)
Original note: Verified closed.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-C3AC-333Sev-2RC1: FIXEDRC4: ✅ FIXEDBetter to open a numeric keyboard when input a Service phone field
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · Closed bug #3
Original device: — not provided — · Originally fixed in: 20.0.0-beta22 (1952)
Original note: Verified closed.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
3b · Failures on the checklist (1)
NEW-3AC-640App crashes during Autofill prompt when reconnecting to server DB via "Use a local database instead" link
Section: Part 4 — RC1 New Bugs Re-Test (AC-638, AC-639, AC-640, AC-646)
Tested device: Galaxy S22
RC1 status: OPEN (new) / RC-8 related
Comments: Reopened, crash issue is fixed, but if I use SSO to log in, save the database offline, then open the offline DB → Settings → Autofill test → click “User name” field → Fill in with password depot, the page shown in the screenshot appears. I cannot enter a password or use SSO to auto-fill. Hence reopen the issue.
3c · New Bugs Discovered (Manual Entry — this round) (2)
NEW #1AC-669Sev-2Editing entry with configured TOTP does not load/mask existing setup key (shows placeholder "New setup key (Base32)")
Tested device: Galaxy S22
Description:
Summary:
When editing an existing entry that already has a TOTP/2FA secret configured, the "One-time code (TOTP)" setup key field does not load or display the existing key. Instead, the field remains empty and shows the hint/placeholder "New setup key (Base32)".
Preconditions:
An entry exists in the database with a valid TOTP setup key configured.
Steps to Reproduce:
Open the entry in edit mode (Edit Entry / Properties).
Locate the "One-time code (TOTP)" / "2FA Secret" setup key input field.
Observe the field content and the visibility toggle (eye icon).
Actual Result:
The existing TOTP setup key is not loaded/displayed in the field.
The input field shows the placeholder/hint: "New setup key (Base32)", making it appear as if no key is configured.
Expected Result:
The existing TOTP setup key should be loaded into the field by default.
For security and consistency with password fields:
The key should be masked by default (e.g., •••••••• / ****).
Clicking the eye icon (visibility toggle) should unmask and show the plaintext Base32 key.
NEW #2AC-671Sev-2SSO connecting Server DB: closing/canceling web login disables "Connect" button permanently
Tested device: Galaxy S22
Description:
Impact
When connecting to a Server DB using Single Sign-On (SSO), if the user navigates back, cancels, or closes the web login popup/browser window, the "Connect" button remains permanently disabled/grayed out. The user is blocked from retrying the connection unless they close/reopen the dialog or restart the application.
Steps to reproduce
Open the app and navigate to Enterprise Server.
Select Single Sign-On (OpenID Connect) as the authentication method.
Tap the "Connect" button.
When the external web browser / OAuth authentication page pops up, close the tab/window or navigate back to the app without completing login.
Return to the app screen and check the state of the "Connect" button.
Expected behaviour
Upon returning to the app or canceling the web authentication flow:
The "Connect" button should clickble again.
Actual behaviour
The "Connect" button remains stuck in a disabled, permanently grayed out and unclickable.
3d · Closed Bugs (Verified Fixed — this round) (11)
CLOSED #1AC-638Sev-2Migration: After setting master password on an imported key-file-only database, unlock screen fails to show password field and reports "The key file is incorrect"
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Migration: After setting master password on an imported key-file-only database, unlock screen fails to show password field and reports "The key file is incorrect"
CLOSED #2AC-639Sev-2Encrypted file & Certificate entry created on Windows client not visible on Android client
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Encrypted file & Certificate entries created in the Windows Client (PD) are not visible in the Android Client (AC).
This prevents users from finding the entry on Android.
CLOSED #3AC-646Sev-2Migration: "Verify and import" button is disabled when importing multiple databases with different keyfiles/passwords
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
When upgrading from v19 to v20 with multiple databases configured with different key files and passwords, the user is prompted to enter passwords and key files for all databases. However, after providing all required credentials, the overall bottom "Verify and import" button remains disabled/grayed out, preventing batch import.
CLOSED #4AC-611Sev-2Second password: Saved field contents lost on next save due to unprotect/reprotect projection discarding undecrypted custom fields and U+FFFD characters
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Fixed and verified.
CLOSED #5AC-612Sev-2Document entry: Selecting file via "Choose file..." does not populate "Original path" and leaves "Save" button disabled
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed.
CLOSED #6AC-613Sev-2Server DB: Category field does not display dropdown / selection menu in entry editor
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed.
CLOSED #7AC-614Sev-2Server DB: TOTP field does not support QR code scanning in entry editor
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed.
CLOSED #8AC-615Sev-2OIDC SSO: passkey unlock launches PD master-password prompt after sign-out (blocks WebAuthn auth)
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed.
CLOSED #9AC-617Sev-2Sync: "Sign in with OIDC" button has no response on "Load fresh copy from the server" dialog
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed
CLOSED #10AC-627Sev-2Entry: Warning message configured on Windows client does not pop up when accessing the entry on Android
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed.
CLOSED #11AC-642Sev-2SSO opening offline Server DB: closing/canceling web login disables "Sign in and open" button permanently
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed.
3e · Blocked Items (0)
No items were blocked this round.
4 · Detailed Results
Part 0b — RC4 Smoke: Google Play Readiness
RC4 is the build that will go to Google Play. This is the smoke pass that must be green before submission. RC-8 failed in RC1 and must be re-tested carefully.
RC-1Sev-0✅ PASS
Release build identity and Play Store readiness
Setup needed: A device with Google Play installed (or the internal test track).
What to test: RC4 is the build that goes to Google Play. Confirm the build identity, that it targets Android 16 (API 36), and that the release configuration is correct.
RC1 status: PASS
Steps
- Open Settings → Version; confirm the exact line reads "20.0.0 RC4".
- Open the Android app info; confirm targetSdkVersion is Android 16 (API 36).
- Confirm the app is not debuggable (no debug banner, no debug menu).
- Confirm screenshot / screen recording is blocked (store release policy).
- Confirm the package name matches the Play listing.
Expected
- Version line is exactly "20.0.0 RC4".
- Targets Android 16 (API 36).
- Not debuggable; no debug surface.
- Screenshots and screen recording are blocked.
- Package name matches the Play listing.
Result
Status: ✅ PASS
Comments:
RC-2Sev-0✅ PASS
First launch on a clean device (no test data)
What to test: RC4 is what a real user will first see. Verify the empty start screen, the first database creation flow and the first entry creation work end to end on a clean device.
RC1 status: PASS
Steps
- Uninstall any previous beta/RC build.
- Install RC4 from the internal test track (or the APK if not yet in Play).
- Open the app; confirm the empty start screen.
- Create a database; add one password entry; lock and unlock.
- Force-close and relaunch; confirm the app comes back locked.
Expected
- Empty start screen on fresh install (no demo data).
- Database creation, entry creation, lock/unlock work.
- After force-close the app restarts locked.
Result
Status: ✅ PASS
Comments:
RC-4Sev-0✅ PASS
Privacy policy and data safety
What to test: Google Play requires a privacy policy link. Confirm it is present, reachable, and matches the Data Safety declaration.
RC1 status: PASS
Steps
- Open Settings → About / Legal; confirm the privacy policy link is present.
- Tap it; confirm the policy opens in a browser and the content matches the app.
- Confirm the Data Safety declaration in Play Console matches what the app actually does.
Expected
- Privacy policy link is present and reachable.
- Policy content matches the app.
- Data Safety declaration is accurate.
Result
Status: ✅ PASS
Comments:
RC-5Sev-1✅ PASS
Android 16 (API 36) edge-to-edge and 3-button navigation
Setup needed: An Android 15 or 16 device with 3-button navigation.
What to test: RC4 targets Android 16. Confirm edge-to-edge drawing on Android 15/16 phones with 3-button navigation.
RC1 status: PASS
Steps
- Open the app on an Android 15/16 device with 3-button navigation.
- Check the status bar, the navigation bar and the keyboard in the main screens.
- Open the autofill window and the passkey dialogs.
- Rotate the device; confirm the layout survives.
Expected
- Edge-to-edge is correct on Android 15/16 with 3-button navigation.
- No content hidden under the status bar or navigation bar.
Result
Status: ✅ PASS
Comments:
RC-6Sev-1✅ PASS
All 27 languages shipped in RC4
What to test: The store release ships all 27 languages (25 machine-translated, AI-proofread). Confirm the language list in the app contains all 27 and that switching works.
RC1 status: PASS
Steps
- Open Settings → App language (Android 13+).
- Confirm all 27 languages are listed.
- Switch to at least three of them; confirm the UI text changes.
- Switch back to English; confirm the app returns to English.
Expected
- All 27 languages are listed.
- Switching languages works without restart.
Result
Status: ✅ PASS
Comments:
RC-7Sev-1✅ PASS
Upgrade from a beta/RC build to RC4 with data kept
Setup needed: A device with a previous build (RC1 / beta22) and a populated database.
What to test: A user who participated in the beta or installed RC1 must be able to update to RC4 without losing data.
RC1 status: PASS
Steps
- Install the previous build; create a database with several entries and a second-password entry.
- Update to RC4 without uninstalling.
- Open the app; confirm the database is still there and unlocks with the same master password.
- Confirm the entries, the second-password entry and the settings are intact.
Expected
- Update installs over the previous build.
- Database, entries, second-password entry and settings are kept.
Result
Status: ✅ PASS
Comments:
RC-8Sev-0✅ PASS
Crash-free cold start and warm start
What to test: A store release must start without crashes. RC1 FAILED with AC-640 (crash during autofill reconnect to server DB). Confirm cold start and warm start on a real device, including after a device reboot.
RC1 status: FAIL — RC1: https://internal.tracker.password-depot.de/browse/AC-640
Steps
- Cold start: force-stop the app, then open it.
- Warm start: background the app, then foreground it.
- Reboot the device; open the app again.
- Autofill reconnect test: let a server DB session expire, trigger autofill, tap "Use a local database instead" — app must NOT crash.
- Watch for any crash, ANR or freeze.
Expected
- Cold start completes without crash.
- Warm start is fast and clean.
- After a device reboot the app starts correctly.
- Autofill reconnect to local DB does not crash.
Result
Status: ✅ PASS
Comments:
Part 0c — RC1 Regression: Beta21 / RC1 Bug Fixes
These bugs were reported in earlier rounds and claimed fixed. RC1 had R18-5 FAIL. Re-test every one on RC4.
R18-1AC-604Sev-0✅ PASS
Key file of the old app — now visible in every key-file prompt
Setup needed: A real 19.x installation with a key-file database.
What to test: Every key-file prompt now lists the key files of the old app and reads the chosen one for that unlock only — nothing is copied or stored.
RC1 status: PASS
Steps
- Install a 19.x build; create/protect a database with a key file.
- Update to RC4; open the takeover flow.
- Open the unlock screen and tap "Choose key file…".
- Verify the key files of the old app are listed.
- Pick the correct one; unlock.
- Repeat in the autofill window and the passkey dialog.
- Change the master password and run a restore; verify the same list appears.
Expected
- Old app's key files are listed in every key-file prompt.
- Chosen one is read for that unlock only.
- Unlock, master-password change and restore all work.
Result
Status: ✅ PASS
Comments:
R18-2AC-605Sev-3✅ PASS
Key-file wording: "Protected with" vs "Additionally protected with"
RC1 status: PASS
Steps
- Open a key-file-only database; check the wording.
- Open a password + key-file database; check the wording in the same three places.
Expected
- Key-file-only → "Protected with a key file".
- Password + key file → "Additionally protected with a key file".
Result
Status: ✅ PASS
Comments:
R18-3AC-606Sev-3✅ PASS
Names after the takeover
Setup needed: A real 19.x migration.
RC1 status: PASS
Steps
- Migrate a database from 19.x with a long path and extension.
- Check the name in the database list.
- Create a backup copy; check its name.
- Open the database and check the header.
Expected
- Database name is the file name without folder and extension.
- Backup copies named "<name> (backup copy n)".
Result
Status: ✅ PASS
Comments:
R18-4AC-607Sev-3✅ PASS
Takeover report lists skipped settings by name
Setup needed: A real 19.x installation with an invalid setting.
RC1 status: PASS
Steps
- Migrate from 19.x with at least one invalid setting.
- Open the takeover report.
Expected
- Skipped settings are listed by name.
Result
Status: ✅ PASS
Comments:
R18-5AC-609Sev-2🔄 IN PROGRESS
WebDAV address with "#" gets its own message
Setup needed: HiDrive account (or a similar WebDAV address with "#").
RC1 status: FAIL — RC1: Reopened, I see that after entering the username, the URL goes to https://webdav.hidrive.strato.com/users/<name>/…/ but it deletes the database.pswe at the end of the entered URL, so the user has to manually re-enter it.
Steps
- Open "Open from cloud…" / "Storage location & sync".
- Paste the browser address of the HiDrive web interface (contains "#").
- Observe the message.
- After entering username, verify that "database.pswe" is NOT stripped from the end of the URL.
Expected
- A specific message says what to enter instead.
- The database file name is preserved at the end of the URL.
Result
Status: 🔄 IN PROGRESS
Comments:
R18-6AC-610Sev-3✅ PASS
Autofill hint names the app's auto-lock value
RC1 status: PASS
Steps
- Set the app auto-lock to a value shorter than the reuse window.
- Open Settings → Autofill & passkeys; find the hint "keep unlocked for …".
Expected
- Hint names the app's auto-lock and shows its value.
Result
Status: ✅ PASS
Comments:
R18-7AC-537 / AC-608Sev-1✅ PASS
Enterprise Server: one-time codes and 2FA against Server 20
Setup needed: Enterprise Server 20 (only).
RC1 status: PASS
Steps
- Sign in to Enterprise Server 20.
- Trigger autofill on a site matching a server entry with a one-time code.
- Verify user name, password and the current one-time code are filled.
- Trigger a 2FA failure; observe the exact reason reported.
Expected
- Autofill fills user name, password and one-time code from the server.
- 2FA failures report the exact reason.
Result
Status: ✅ PASS
Comments:
Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)
Estimated time: 45–60 minutes. Run on every device you test. RC1 had A2 FAIL.
A1✅ PASS
First Launch & Database Creation
RC1 status: PASS
Steps
- Fresh install (or update): open the app.
- Create a database with a name and a test master password.
- Confirm the empty entry list is shown.
- Relaunch the app.
- Enter the master password; confirm unlock.
- Enter a wrong master password.
Expected
- Empty list shown after creation.
- After relaunch, app is locked.
- Correct password unlocks; wrong password gives a clear error message.
Result
Status: ✅ PASS
Comments:
A2✅ PASS
Entries of Several Types
RC1 status: FAIL — RC1: https://internal.tracker.password-depot.de/browse/AC-639
Steps
- Create the following entries: password entry, credit card (PIN/CVV), identity entry, information entry, entry with a protected custom field.
- While typing secret fields, verify keyboard behavior.
- Open detail view for each entry.
- Edit each entry and re-save.
- Windows interop: create encrypted file on Windows, verify it is visible on Android (AC-639).
Expected
- Secret fields use a password keyboard: no word suggestions, no swipe input.
- Detail view shows values readable (matching Windows).
- Nothing lost after edit and save.
- Encrypted file created on Windows is visible on Android.
Result
Status: ✅ PASS
Comments:
A3✅ PASS
Folders, Search, Trash
RC1 status: PASS
Steps
- Create two folders.
- Move entries between them.
- Search by title, username, and URL.
- Delete an entry (move to trash).
- Restore it from the recycle bin.
Expected
- All operations complete without errors.
- Restored entry appears back in its original location.
Result
Status: ✅ PASS
Comments:
A4✅ PASS
Locking
RC1 status: PASS
Steps
- Background the app and return quickly (within the auto-lock time).
- Stay away past the auto-lock time.
- Force-close the app from Recents.
- Relaunch.
Expected
- Quick background: app stays open.
- After timeout: app is locked.
- After force-close: next start is always locked.
Result
Status: ✅ PASS
Comments:
A5✅ PASS
Biometric Unlock + Invalidation
RC1 status: PASS
Steps
- Enable Settings → Security → Biometric unlock.
- Lock the database.
- Unlock using fingerprint/face.
- Enroll an additional fingerprint in the Android system settings.
- Return to the app.
Expected
- Biometric unlock works in step 3.
- After enrolling new fingerprint: app refuses biometrics with an explanation.
- Can re-enable biometric unlock afterwards.
Result
Status: ✅ PASS
Comments:
A6✅ PASS
Clipboard
RC1 status: PASS
Steps
- Copy a password from the detail view.
- Check if a countdown notification appears.
- Paste the password in another app.
- Wait 30 seconds; attempt to paste again.
- Try the "Clear now" button in the notification.
Expected
- Countdown notification appears immediately.
- Password can be pasted within 30 seconds.
- After 30 seconds: password can no longer be pasted.
- "Clear now" clears immediately.
Result
Status: ✅ PASS
Comments:
A7✅ PASS
Autofill in Your Daily Browser
Note: Chrome 131+ extra step required: Chrome → Settings → Autofill services → "Autofill using another service" → restart Chrome.
RC1 status: PASS
Steps
- Enable Settings → Autofill service.
- Open Settings → Autofill test; confirm the suggestion appears.
- Navigate to a test account login page in your browser.
- Verify autofill suggestion appears.
- Fill with Password Depot.
- Log in with a new credential typed manually; confirm save/update prompt appears.
- Negative check: navigate to a look-alike domain; confirm the entry is NOT offered.
Expected
- Suggestion appears on matching domain.
- Save/update flow works.
- No suggestion offered for non-matching domains.
Result
Status: ✅ PASS
Comments:
A8✅ PASS
Autofill in One App
RC1 status: PASS
Steps
- Open any app with a login screen (use a test account).
- Trigger autofill.
Expected
- Autofill works or cleanly offers nothing — no crash, no wrong entry offered.
Result
Status: ✅ PASS
Comments:
A9✅ PASS
Appearance, Language, Rotation, Tablet
RC1 status: PASS
Steps
- Switch appearance: dark → light → system mode.
- Switch app language DE ↔ EN.
- Rotate the device while unlocked.
- (Tablet/foldable only) Verify the two-pane list+detail layout.
Expected
- All appearance/language switches work without restart.
- Rotation preserves state.
- Two-pane layout is correct on tablets.
Result
Status: ✅ PASS
Comments:
A10✅ PASS
Stability & Error Visibility
What to test: Any crash, freeze, or silently swallowed error is a top report.
RC1 status: PASS
Steps
- If any of the above occur, open Support data immediately.
- Copy the version line and any listed events.
- File a Jira Bug with Sev-0 and attach the support data.
Expected
- No crashes, freezes, or silently swallowed errors.
Result
Status: ✅ PASS
Comments:
Part 3 — Focus Blocks C1–C11
Complete the blocks assigned to you, or any you have the setup for. RC1: all C1–C11 PASS.
C1✅ PASS
TOTP
Setup needed: A test account with 2FA / TOTP setup, and a reference authenticator app.
RC1 status: PASS
Steps
- Add a TOTP secret to a test entry using the entry editor.
- Use "Scan QR code" (camera or photo) to add the TOTP secret.
- Compare the 6-digit code with a reference authenticator for at least 3 consecutive periods.
- With autofill: open the 2FA field on a login page; confirm the code is offered only into the one-time-code field.
Expected
- Codes match the reference authenticator for ≥3 periods.
- Code offered only into OTP fields.
Result
Status: ✅ PASS
Comments:
C2✅ PASS
Passkeys (Android 14+)
Setup needed: Android 14+, device screen lock enabled. Test site: https://webauthn.io
RC1 status: PASS
Steps
- Settings → Passkey provider → select Password Depot. Verify the row shows "Enabled".
- On webauthn.io: register a new passkey.
- Sign in with the passkey using the same database.
- Move the passkey entry to the trash.
- Attempt sign-in again → expect "No matching passkey in the database".
- Restore the passkey entry.
- Attempt sign-in again → confirm it works.
Expected
- All steps above behave as described.
Result
Status: ✅ PASS
Comments:
C3✅ PASS
WebDAV Sync
Setup needed: A real Nextcloud and/or Apache WebDAV server over HTTPS.
RC1 status: PASS
Steps
- Link the WebDAV server.
- Perform the initial database upload.
- Edit an entry on Android; sync; verify on Windows.
- Edit the same entry on both Android and Windows simultaneously.
- Sync from Android.
Expected
- Initial upload succeeds.
- Concurrent edit on same entry: a conflicted copy appears on Android.
Result
Status: ✅ PASS
Comments:
C4✅ PASS
Windows Interop
Setup needed: Windows Password Depot 19 and the same database accessible on both.
RC1 status: PASS
Steps
- Open the same .pswe file alternately in Windows PD 19 and Android.
- Verify that entries with umlauts/emoji, folders, attachments, TAN lists, entry history, custom icons and a second-password entry survive both directions.
- Set an expiry date on Android; open in Windows; confirm the date is preserved.
Expected
- All content survives both directions unchanged.
Result
Status: ✅ PASS
Comments:
C5✅ PASS
Attachments
RC1 status: PASS
Steps
- Attach a photo (a few MB) to an entry; reopen and export it.
- Attach a PDF (a few MB) to an entry; reopen and export it.
- Attempt to attach a file over 25 MB.
Expected
- Photo and PDF attach, export, and open correctly.
- File over 25 MB: refused with a clear message, no crash.
Result
Status: ✅ PASS
Comments:
C6✅ PASS
Multi-Database & Master Password Change
What to test: The app's copy of every database lives in the app's private storage. A database created "on this device" has no external file — removing it deletes the only copy.
RC1 status: PASS
Steps
- Create a second database; switch between both databases.
- Export a copy of the second database; open that file via "Open database file…".
- Remove THAT entry from the app — the file in Downloads must still exist — and open it again.
- Change the master password of a test database.
- Attempt to unlock with the old password.
Expected
- Switching between databases works seamlessly.
- "Remove from app" does not delete the external file.
- Old password is rejected after change.
Result
Status: ✅ PASS
Comments:
C7✅ PASS
Backup & Restore
RC1 status: PASS
Steps
- Navigate to Databases & sync → Backup copies; create a backup of a test database.
- Make a few changes to the database.
- Restore an earlier backup copy.
- Enter a wrong password during restore; check for throttle and message.
- Enter the correct password; confirm restore.
- Attempt to restore a deliberately corrupted backup file.
Expected
- Correct password restores successfully; current state saved before restore.
- Wrong password: throttle + clear message.
- Corrupted backup: refused with error; active database untouched.
Result
Status: ✅ PASS
Comments:
C8✅ PASS
Enterprise Thin Client
Setup needed: Office test server (Enterprise Server 20).
RC1 status: PASS
Steps
- Open the app → "Enterprise server…" on the start screen.
- Enter the server address and port; log in.
- On first connect: verify the TLS fingerprint confirmation dialog appears.
- Browse and search entries on the server.
- Edit an entry and save.
Expected
- TLS fingerprint dialog appears on first connect.
- Login succeeds; server/port remembered.
- Browse, search, and edit work.
Result
Status: ✅ PASS
Comments:
C9✅ PASS
Enterprise Offline Copy
Setup needed: Enterprise Server 20, TCP port 25020, a database with the offline right granted.
RC1 status: PASS
Steps
- Sign in to the server; tap "Save offline copy…" on the database list.
- Enter the server password.
- Tap "Load databases" — confirm the TLS fingerprint once.
- Pick a database; confirm the copy is saved.
- Sign out; tap "Open offline copy" on the login screen.
- Create/edit an entry offline; note the waiting-changes counter.
- Settings → Sync… → "Send changes to the server".
Expected
- All steps above behave as described.
Result
Status: ✅ PASS
Comments:
C10✅ PASS
Enterprise Single Sign-On (OpenID Connect / Entra ID)
Setup needed: Enterprise Server 20 with a configured OpenID Connect or Entra ID sign-in provider.
RC1 status: PASS
Steps
- Choose "Single sign-on (OpenID Connect / Entra ID)" in the Enterprise login; tap "Connect".
- Complete sign-in in the browser.
- Sign out; use "Sign in with a different account".
- Start a sign-in and cancel it in the browser.
- Sign in with an account the server does not know.
Expected
- All scenarios above behave as described.
Result
Status: ✅ PASS
Comments:
C11✅ PASS
Hand-Over of Previous-App Offline Changes
Setup needed: Enterprise Server 20, TCP port 25020.
RC1 status: PASS
Steps
- Start with the previous Password Depot for Android app installed and an Enterprise database with unsent offline changes.
- Update to RC4; open "Import from previous app".
- Verify the report names the number of unsent changes.
- Tap "Send to the server…".
- Confirm the note disappears and the changes are on the server.
Expected
- All steps above behave as described.
Result
Status: ✅ PASS
Comments:
Part 4 — RC1 New Bugs Re-Test (AC-638, AC-639, AC-640, AC-646)
These are the 4 New Bugs discovered manually during RC1. Each must be re-tested on RC4.
NEW-1AC-638Sev-2✅ PASS
Migration: After setting master password on an imported key-file-only database, unlock screen fails to show password field and reports "The key file is incorrect"
Setup needed: A 19.x key-file-only database for migration.
RC1 status: OPEN (new)
Steps
- Import the key-file-only database from 19.x.
- Set a master password on the imported database.
- Lock the database.
- Attempt to unlock: verify the password field is shown.
- Enter the master password and unlock.
Expected
- Unlock screen shows the password field.
- No "The key file is incorrect" error when using the correct master password.
- Unlock succeeds.
Result
Status: ✅ PASS
Comments:
NEW-2AC-639Sev-2✅ PASS
Encrypted file created on Windows client not visible on Android client
Setup needed: Windows client with the same database; Android RC4.
RC1 status: OPEN (new)
Steps
- On Windows, create an encrypted file entry / encrypted file in the database.
- Sync or open the same database on Android.
- Check whether the encrypted file is visible.
- Open it if visible.
Expected
- Encrypted file created on Windows is visible on Android.
- The file can be opened / exported.
Result
Status: ✅ PASS
Comments:
NEW-3AC-640Sev-2❌ FAIL
App crashes during Autofill prompt when reconnecting to server DB via "Use a local database instead" link
Setup needed: Enterprise Server DB; let the session expire.
RC1 status: OPEN (new) / RC-8 related
Steps
- Sign in to the server DB.
- Wait for the server session to expire (or force it).
- Trigger autofill in a browser / app.
- Tap "Use a local database instead".
- Verify the app navigates to local database selection (NOT server DB login).
- If a dialog appears, enter credentials and tap Connect — app must NOT crash.
Expected
- Tapping "Use a local database instead" opens local database selection.
- No server DB login dialog appears unexpectedly.
- No crash when connecting.
Result
Status: ❌ FAIL
Tested device: Galaxy S22
Comments:
NEW-4AC-646Sev-2✅ PASS
Migration: "Verify and import" button is disabled when importing multiple databases with different keyfiles/passwords
Setup needed: A v19 installation with multiple databases using different key files and passwords.
RC1 status: OPEN (new)
Steps
- Start the v19 → v20 (RC4) upgrade.
- When prompted, enter passwords and key files for all databases.
- After providing all required credentials, check the bottom "Verify and import" button.
- Tap it and complete the import.
Expected
- "Verify and import" button becomes enabled after all credentials are provided.
- Batch import completes successfully.
Result
Status: ✅ PASS
Comments:
Part 5 — RC1 Closed Bugs Regression (14)
These 14 bugs were closed and verified in RC1. Confirm no regression on RC4.
REG-1AC-608Sev-2✅ PASS
SSO / OpenID Connect login fails on Android client when 2FA is enabled on Enterprise Server
RC1 status: CLOSED
Steps
- Sign in with SSO/OpenID Connect when 2FA is enabled on Enterprise Server 20.
- Confirm login succeeds.
Expected
- SSO login works with 2FA enabled.
Result
Status: ✅ PASS
Comments:
REG-2AC-604Sev-2✅ PASS
Migration: key file of an imported legacy database can never be selected again - user locked out
RC1 status: CLOSED
Steps
- Migrate a 19.x key-file database.
- Verify the key file can be selected again in unlock prompts.
Expected
- Key file is selectable; user is not locked out.
Result
Status: ✅ PASS
Comments:
REG-3AC-605Sev-2✅ PASS
Key-file-only databases are labelled "Also protected by a key file", contradicting the sentence below it
RC1 status: CLOSED
Steps
- Open a key-file-only database.
- Check the wording.
Expected
- Correct wording: "Protected with a key file".
Result
Status: ✅ PASS
Comments:
REG-4AC-606Sev-2✅ PASS
Imported legacy databases keep their file extension and folder prefix as the database name
RC1 status: CLOSED
Steps
- Migrate a 19.x database with long path/extension.
- Check the name in the database list.
Expected
- Database name is file name without folder and extension.
Result
Status: ✅ PASS
Comments:
REG-5AC-610Sev-2✅ PASS
Settings: "Keep autofill unlocked for..." does not mention that "Auto-lock" ends the autofill grace period earlier
RC1 status: CLOSED
Steps
- Open Settings → Autofill & passkeys.
- Check the hint text.
Expected
- Hint names auto-lock and shows its value.
Result
Status: ✅ PASS
Comments:
REG-6AC-537Sev-2✅ PASS
Autofill: Autofill fails to fill TOTP when Username, Password, and TOTP are on the same page (Server DB only)
RC1 status: CLOSED (Firefox limitation)
Steps
- Server DB; open a page with username, password and TOTP on the same page.
- Trigger autofill.
Expected
- TOTP is filled into the OTP field where supported.
Result
Status: ✅ PASS
Comments:
REG-7AC-620Sev-2✅ PASS
Autofill: Modifying username after autofill and logging in creates a new entry instead of updating existing entry
RC1 status: CLOSED
Steps
- Autofill username/password; change username; log in.
- Tap Update when prompted.
Expected
- Existing entry is updated; no new entry.
Result
Status: ✅ PASS
Comments:
REG-8AC-623Sev-2✅ PASS
Recycle Bin: Add button/option to empty or clean recycle bin
RC1 status: CLOSED
Steps
- Open recycle bin.
- Look for empty/clean action.
Expected
- Button/option available to empty whole recycle bin.
Result
Status: ✅ PASS
Comments:
REG-9AC-624Sev-2✅ PASS
Autofill: Autofill in Edge browser fails to detect target URL (unknown target)
RC1 status: CLOSED
Steps
- Open Edge; navigate to login page; trigger autofill.
Expected
- Target URL detected; matching entry suggested.
Result
Status: ✅ PASS
Comments:
REG-10AC-625Sev-2✅ PASS
Server DB: TOTP field/code is not displayed in entry details view on Android client
RC1 status: CLOSED
Steps
- Server DB entry with TOTP; open details.
Expected
- TOTP field and current code displayed.
Result
Status: ✅ PASS
Comments:
REG-11AC-626Sev-2✅ PASS
Entry Details: Importance set to "High" is incorrectly displayed as "Low" on Android client
RC1 status: CLOSED
Steps
- Entry with Importance High; open on Android.
Expected
- Importance badge reads "High".
Result
Status: ✅ PASS
Comments:
REG-12AC-628Sev-2✅ PASS
Server DB: Redundant "Expires" field displayed in DETAILS block for Credit Card entries created via Windows Client in ES DB
RC1 status: CLOSED
Steps
- Credit Card entry from Windows ES DB; open on Android.
Expected
- No redundant Expires field.
Result
Status: ✅ PASS
Comments:
REG-13AC-629Sev-2✅ PASS
Unify entry field/item names across new clients with Windows client
RC1 status: CLOSED
Steps
- Compare field/item labels Android vs Windows.
Expected
- Names match Windows client.
Result
Status: ✅ PASS
Comments:
REG-14AC-622Sev-2✅ PASS
Server DB not able to set second password on new entry or edit entry
RC1 status: CLOSED
Steps
- Server DB; create/edit entry; set second password.
Expected
- Second password can be set and saved.
Result
Status: ✅ PASS
Comments:
5 · Device Matrix Contribution
| Dimension | Variant | Covered | Notes |
|---|
| Keyboard | Gboard | ✅ | |
| Keyboard | Samsung Keyboard | ✅ | |
| Keyboard | SwiftKey | ✅ | |
| Browser | Chrome | ✅ | |
| Browser | Edge | ✅ | |
| Browser | Firefox | ✅ | |
| Browser | Samsung Internet | — | |
| Autofill style | Android 11+ inline chips (note which you saw) | ✅ | |
| Autofill style | Android ≤13 dropdown | ✅ | |
| Clipboard | Samsung clipboard behavior | ✅ | |
| Clipboard | Pixel clipboard behavior | n/a | |
| Clipboard | Xiaomi clipboard behavior | n/a | |
| Biometrics | Fingerprint | ✅ | |
| Biometrics | Face unlock | ✅ | |
| Biometrics | Both enrolled | ✅ | |
| OEM quirks | Xiaomi/HyperOS battery saver — auto-lock reliable? | n/a | |
| OEM quirks | Samsung battery saver — session killed mid-edit? | ✅ | |
| Form factor | Phone | ✅ | |
| Form factor | Tablet (≥ 600 dp) | n/a | |
| Form factor | Foldable | n/a | |
| Storage | FTPS / FTPES | ✅ | |
| Storage | HiDrive | ✅ | |
| Migration | 19.x migration with key-file database | ✅ | |
| RC4 Smoke | Google Play internal test track install | ✅ | |
6 · Reporting Reference
| Jira Project | Android Client (AC) |
|---|
| Affects Version | 20.0.0 |
|---|
| Build line | 20.0.0 RC4 |
|---|
| Release | RC4 · Google Play submission pending |
|---|
| Severity 0 | crash · data loss · lock-out |
|---|
| Severity 1 | feature wrong or unusable |
|---|
| Severity 2 | wrong, has a workaround |
|---|
| Severity 3 | visual / text |
|---|
Support data: lock the app → tap "Support data…" on the unlock screen.