Password Depot for Android — RC4 QA Test Report

Build 20.0.0 RC4 · Release Candidate 4 · Regression of 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · Generated 9/28/2026, 6:59:55 PM

1 · Environment

Device / AndroidGalaxy S22
KeyboardSamsung Keyboard 5.9.12
Browser(s)Chrome 152, Edge 152, Firefox 155
Build line20.0.0 RC4 (2000)
TesterSheva Ma
Date started2026-Sep-28

2 · Summary

BlockTotal✅ Pass/Fixed❌ Fail🚫 Blocked⏭️ Skip🔄 In Progress⬜ Pending
Part 0a — Reported Bugs Re-Verification (from RC1 report)111100000
Part 0b — RC4 Smoke: Google Play Readiness7700000
Part 0c — RC1 Regression: Beta21 / RC1 Bug Fixes7600010
Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)101000000
Part 3 — Focus Blocks C1–C11111100000
Part 4 — RC1 New Bugs Re-Test (AC-638, AC-639, AC-640, AC-646)4310000
Part 5 — RC1 Closed Bugs Regression (14)141400000
Total646210010
Items tested / total63 / 64
Pass rate (of decided items)98%
Failures1
Blocked items0
Reported bugs re-verified: fixed11 / 11
Reported bugs re-verified: still broken0 / 11
New bugs discovered (manual entry)2
Closed bugs (verified fixed this round)11

3a · Reported Bugs Re-Verification (from RC1 report) (11)

These are the bugs from the RC1 report. Each entry shows the original report details and the RC4 re-verification verdict.

New Bugs from RC1 report (8)

REV-N1AC-620Sev-2RC1: FIXEDRC4: ✅ FIXEDAutofill: Modifying username after autofill and logging in creates a new entry instead of updating existing entry
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #1
Original device: Galaxy S22, Android 15
Original note: Problem Summary: After autofilling username and password in the Chrome browser, if the user changes the username and logs in, Password Depot prompts to update the entry. Clicking Update creates a new entry instead of updating the existing one.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N2AC-623Sev-2RC1: FIXEDRC4: ✅ FIXEDRecycle Bin: Add button/option to empty or clean recycle bin
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #2
Original device: NA
Original note: Currently in the Android client Recycle Bin view, there is no option or button to empty/clean the entire recycle bin. Users have to handle items individually.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N3AC-624Sev-2RC1: FIXEDRC4: ✅ FIXEDAutofill: Autofill in Edge browser fails to detect target URL (unknown target)
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #3
Original device: Samsung Galaxy S22
Original note: Autofill in Microsoft Edge on Android does not detect the target website URL. Users see an "unknown target" message, and the matching saved password entry is not automatically suggested.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N4AC-625Sev-2RC1: FIXEDRC4: ✅ FIXEDServer DB: TOTP field/code is not displayed in entry details view on Android client
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #4
Original device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Original note: When viewing a password entry stored in an Enterprise Server database on the Android client, the TOTP field and generated one-time code do not display in the entry details view, even though the TOTP secret is configured and working properly on the Windows client.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N5AC-626Sev-2RC1: FIXEDRC4: ✅ FIXEDEntry Details: Importance set to "High" is incorrectly displayed as "Low" on Android client
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #5
Original device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Original note: When an entry is created or updated with its Importance level set to "High" (via Windows client or Server DB), the Android client incorrectly displays the Importance badge as "Low" under the DETAILS section.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N6AC-627Sev-2RC1: BLOCKEDRC4: ✅ FIXEDEntry: Warning message configured on Windows client does not pop up when accessing the entry on Android
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #6
Original device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Original note: When accessing an entry with a configured warning message, a warning prompt/dialog should pop up displaying the warning text, requiring user confirmation before displaying details or copying credentials (consistent with the Windows client behavior).
RC1 note: RC1: Need to wait ES-1002 ready for testing.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N7AC-628Sev-2RC1: FIXEDRC4: ✅ FIXEDServer DB: Redundant "Expires" field displayed in DETAILS block for Credit Card entries created via Windows Client in ES DB
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #7
Original device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Original note: The DETAILS block should not display a redundant/empty Expires field for Credit Card entries.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-N8AC-629Sev-2RC1: FIXEDRC4: ✅ FIXEDUnify entry field/item names across new clients with Windows client
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · New bug #8
Original device: Samsung Galaxy S22, Google Pixel 10 Pro, Xiaomi Redmi Note 14 Pro, Samsung Galaxy Tab S11
Original note: Feature request: Unify entry field/item names across new clients with Windows client.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —

Closed Bugs from RC1 report (3)

REV-C1AC-440Sev-2RC1: FIXEDRC4: ✅ FIXEDAndroid Client becomes slow and laggy when database contains 20,000+ entries
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · Closed bug #1
Original device: — not provided — · Originally fixed in: 20.0.0-beta22 (1952)
Original note: Verified closed
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-C2AC-430Sev-2RC1: FIXEDRC4: ✅ FIXEDSSPI login mode - User Logon Name Format settings do not match expected behavior for Simple, Domain\sAMAccountName, and UPN modes
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · Closed bug #2
Original device: — not provided — · Originally fixed in: 20.0.0-beta22 (1952)
Original note: Verified closed.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —
REV-C3AC-333Sev-2RC1: FIXEDRC4: ✅ FIXEDBetter to open a numeric keyboard when input a Service phone field
Originally reported in: 20.0.0 RC1 (2000) · RC1 QA Report · 2026-09-24 · Closed bug #3
Original device: — not provided — · Originally fixed in: 20.0.0-beta22 (1952)
Original note: Verified closed.
RC4 re-verification — device: — not provided —
RC4 re-verification comments:
— none —

3b · Failures on the checklist (1)

NEW-3AC-640App crashes during Autofill prompt when reconnecting to server DB via "Use a local database instead" link
Section: Part 4 — RC1 New Bugs Re-Test (AC-638, AC-639, AC-640, AC-646)
Tested device: Galaxy S22
RC1 status: OPEN (new) / RC-8 related
Comments: Reopened, crash issue is fixed, but if I use SSO to log in, save the database offline, then open the offline DB → Settings → Autofill test → click “User name” field → Fill in with password depot, the page shown in the screenshot appears. I cannot enter a password or use SSO to auto-fill. Hence reopen the issue.

3c · New Bugs Discovered (Manual Entry — this round) (2)

NEW #1AC-669Sev-2Editing entry with configured TOTP does not load/mask existing setup key (shows placeholder "New setup key (Base32)")
Tested device: Galaxy S22
Description:
Summary:
When editing an existing entry that already has a TOTP/2FA secret configured, the "One-time code (TOTP)" setup key field does not load or display the existing key. Instead, the field remains empty and shows the hint/placeholder "New setup key (Base32)".

Preconditions:

An entry exists in the database with a valid TOTP setup key configured.

Steps to Reproduce:

Open the entry in edit mode (Edit Entry / Properties).

Locate the "One-time code (TOTP)" / "2FA Secret" setup key input field.

Observe the field content and the visibility toggle (eye icon).

Actual Result:

The existing TOTP setup key is not loaded/displayed in the field.

The input field shows the placeholder/hint: "New setup key (Base32)", making it appear as if no key is configured.

Expected Result:

The existing TOTP setup key should be loaded into the field by default.

For security and consistency with password fields:

The key should be masked by default (e.g., •••••••• / ****).

Clicking the eye icon (visibility toggle) should unmask and show the plaintext Base32 key.
NEW #2AC-671Sev-2SSO connecting Server DB: closing/canceling web login disables "Connect" button permanently
Tested device: Galaxy S22
Description:
Impact
When connecting to a Server DB using Single Sign-On (SSO), if the user navigates back, cancels, or closes the web login popup/browser window, the "Connect" button remains permanently disabled/grayed out. The user is blocked from retrying the connection unless they close/reopen the dialog or restart the application.

Steps to reproduce
Open the app and navigate to Enterprise Server.

Select Single Sign-On (OpenID Connect) as the authentication method.

Tap the "Connect" button.

When the external web browser / OAuth authentication page pops up, close the tab/window or navigate back to the app without completing login.

Return to the app screen and check the state of the "Connect" button.

Expected behaviour
Upon returning to the app or canceling the web authentication flow:

The "Connect" button should clickble again.

Actual behaviour
The "Connect" button remains stuck in a disabled, permanently grayed out and unclickable.

3d · Closed Bugs (Verified Fixed — this round) (11)

CLOSED #1AC-638Sev-2Migration: After setting master password on an imported key-file-only database, unlock screen fails to show password field and reports "The key file is incorrect"
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Migration: After setting master password on an imported key-file-only database, unlock screen fails to show password field and reports "The key file is incorrect"
CLOSED #2AC-639Sev-2Encrypted file & Certificate entry created on Windows client not visible on Android client
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Encrypted file & Certificate entries created in the Windows Client (PD) are not visible in the Android Client (AC).
This prevents users from finding the entry on Android.
CLOSED #3AC-646Sev-2Migration: "Verify and import" button is disabled when importing multiple databases with different keyfiles/passwords
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
When upgrading from v19 to v20 with multiple databases configured with different key files and passwords, the user is prompted to enter passwords and key files for all databases. However, after providing all required credentials, the overall bottom "Verify and import" button remains disabled/grayed out, preventing batch import.
CLOSED #4AC-611Sev-2Second password: Saved field contents lost on next save due to unprotect/reprotect projection discarding undecrypted custom fields and U+FFFD characters
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Fixed and verified.
CLOSED #5AC-612Sev-2Document entry: Selecting file via "Choose file..." does not populate "Original path" and leaves "Save" button disabled
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed.
CLOSED #6AC-613Sev-2Server DB: Category field does not display dropdown / selection menu in entry editor
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed.
CLOSED #7AC-614Sev-2Server DB: TOTP field does not support QR code scanning in entry editor
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed.
CLOSED #8AC-615Sev-2OIDC SSO: passkey unlock launches PD master-password prompt after sign-out (blocks WebAuthn auth)
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed.
CLOSED #9AC-617Sev-2Sync: "Sign in with OIDC" button has no response on "Load fresh copy from the server" dialog
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed
CLOSED #10AC-627Sev-2Entry: Warning message configured on Windows client does not pop up when accessing the entry on Android
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed.
CLOSED #11AC-642Sev-2SSO opening offline Server DB: closing/canceling web login disables "Sign in and open" button permanently
Fixed in build: 20.0.0 RC4
Verified on device: Galaxy S22
Resolution note:
Verified and closed.

3e · Blocked Items (0)

No items were blocked this round.

4 · Detailed Results

Part 0b — RC4 Smoke: Google Play Readiness

RC4 is the build that will go to Google Play. This is the smoke pass that must be green before submission. RC-8 failed in RC1 and must be re-tested carefully.

RC-1Sev-0✅ PASS
Release build identity and Play Store readiness
Setup needed: A device with Google Play installed (or the internal test track).
What to test: RC4 is the build that goes to Google Play. Confirm the build identity, that it targets Android 16 (API 36), and that the release configuration is correct.
RC1 status: PASS
Steps
  1. Open Settings → Version; confirm the exact line reads "20.0.0 RC4".
  2. Open the Android app info; confirm targetSdkVersion is Android 16 (API 36).
  3. Confirm the app is not debuggable (no debug banner, no debug menu).
  4. Confirm screenshot / screen recording is blocked (store release policy).
  5. Confirm the package name matches the Play listing.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC-2Sev-0✅ PASS
First launch on a clean device (no test data)
What to test: RC4 is what a real user will first see. Verify the empty start screen, the first database creation flow and the first entry creation work end to end on a clean device.
RC1 status: PASS
Steps
  1. Uninstall any previous beta/RC build.
  2. Install RC4 from the internal test track (or the APK if not yet in Play).
  3. Open the app; confirm the empty start screen.
  4. Create a database; add one password entry; lock and unlock.
  5. Force-close and relaunch; confirm the app comes back locked.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC-4Sev-0✅ PASS
Privacy policy and data safety
What to test: Google Play requires a privacy policy link. Confirm it is present, reachable, and matches the Data Safety declaration.
RC1 status: PASS
Steps
  1. Open Settings → About / Legal; confirm the privacy policy link is present.
  2. Tap it; confirm the policy opens in a browser and the content matches the app.
  3. Confirm the Data Safety declaration in Play Console matches what the app actually does.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC-5Sev-1✅ PASS
Android 16 (API 36) edge-to-edge and 3-button navigation
Setup needed: An Android 15 or 16 device with 3-button navigation.
What to test: RC4 targets Android 16. Confirm edge-to-edge drawing on Android 15/16 phones with 3-button navigation.
RC1 status: PASS
Steps
  1. Open the app on an Android 15/16 device with 3-button navigation.
  2. Check the status bar, the navigation bar and the keyboard in the main screens.
  3. Open the autofill window and the passkey dialogs.
  4. Rotate the device; confirm the layout survives.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC-6Sev-1✅ PASS
All 27 languages shipped in RC4
What to test: The store release ships all 27 languages (25 machine-translated, AI-proofread). Confirm the language list in the app contains all 27 and that switching works.
RC1 status: PASS
Steps
  1. Open Settings → App language (Android 13+).
  2. Confirm all 27 languages are listed.
  3. Switch to at least three of them; confirm the UI text changes.
  4. Switch back to English; confirm the app returns to English.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC-7Sev-1✅ PASS
Upgrade from a beta/RC build to RC4 with data kept
Setup needed: A device with a previous build (RC1 / beta22) and a populated database.
What to test: A user who participated in the beta or installed RC1 must be able to update to RC4 without losing data.
RC1 status: PASS
Steps
  1. Install the previous build; create a database with several entries and a second-password entry.
  2. Update to RC4 without uninstalling.
  3. Open the app; confirm the database is still there and unlocks with the same master password.
  4. Confirm the entries, the second-password entry and the settings are intact.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC-8Sev-0✅ PASS
Crash-free cold start and warm start
What to test: A store release must start without crashes. RC1 FAILED with AC-640 (crash during autofill reconnect to server DB). Confirm cold start and warm start on a real device, including after a device reboot.
RC1 status: FAIL — RC1: https://internal.tracker.password-depot.de/browse/AC-640
Steps
  1. Cold start: force-stop the app, then open it.
  2. Warm start: background the app, then foreground it.
  3. Reboot the device; open the app again.
  4. Autofill reconnect test: let a server DB session expire, trigger autofill, tap "Use a local database instead" — app must NOT crash.
  5. Watch for any crash, ANR or freeze.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 0c — RC1 Regression: Beta21 / RC1 Bug Fixes

These bugs were reported in earlier rounds and claimed fixed. RC1 had R18-5 FAIL. Re-test every one on RC4.

R18-1AC-604Sev-0✅ PASS
Key file of the old app — now visible in every key-file prompt
Setup needed: A real 19.x installation with a key-file database.
What to test: Every key-file prompt now lists the key files of the old app and reads the chosen one for that unlock only — nothing is copied or stored.
RC1 status: PASS
Steps
  1. Install a 19.x build; create/protect a database with a key file.
  2. Update to RC4; open the takeover flow.
  3. Open the unlock screen and tap "Choose key file…".
  4. Verify the key files of the old app are listed.
  5. Pick the correct one; unlock.
  6. Repeat in the autofill window and the passkey dialog.
  7. Change the master password and run a restore; verify the same list appears.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R18-2AC-605Sev-3✅ PASS
Key-file wording: "Protected with" vs "Additionally protected with"
RC1 status: PASS
Steps
  1. Open a key-file-only database; check the wording.
  2. Open a password + key-file database; check the wording in the same three places.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R18-3AC-606Sev-3✅ PASS
Names after the takeover
Setup needed: A real 19.x migration.
RC1 status: PASS
Steps
  1. Migrate a database from 19.x with a long path and extension.
  2. Check the name in the database list.
  3. Create a backup copy; check its name.
  4. Open the database and check the header.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R18-4AC-607Sev-3✅ PASS
Takeover report lists skipped settings by name
Setup needed: A real 19.x installation with an invalid setting.
RC1 status: PASS
Steps
  1. Migrate from 19.x with at least one invalid setting.
  2. Open the takeover report.
Expected
Result
Status: ✅ PASS
Comments:
— none —
R18-5AC-609Sev-2🔄 IN PROGRESS
WebDAV address with "#" gets its own message
Setup needed: HiDrive account (or a similar WebDAV address with "#").
RC1 status: FAIL — RC1: Reopened, I see that after entering the username, the URL goes to https://webdav.hidrive.strato.com/users/<name>/…/ but it deletes the database.pswe at the end of the entered URL, so the user has to manually re-enter it.
Steps
  1. Open "Open from cloud…" / "Storage location & sync".
  2. Paste the browser address of the HiDrive web interface (contains "#").
  3. Observe the message.
  4. After entering username, verify that "database.pswe" is NOT stripped from the end of the URL.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
R18-6AC-610Sev-3✅ PASS
Autofill hint names the app's auto-lock value
RC1 status: PASS
Steps
  1. Set the app auto-lock to a value shorter than the reuse window.
  2. Open Settings → Autofill & passkeys; find the hint "keep unlocked for …".
Expected
Result
Status: ✅ PASS
Comments:
— none —
R18-7AC-537 / AC-608Sev-1✅ PASS
Enterprise Server: one-time codes and 2FA against Server 20
Setup needed: Enterprise Server 20 (only).
RC1 status: PASS
Steps
  1. Sign in to Enterprise Server 20.
  2. Trigger autofill on a site matching a server entry with a one-time code.
  3. Verify user name, password and the current one-time code are filled.
  4. Trigger a 2FA failure; observe the exact reason reported.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 1 — Core Pass: A1–A10 (Every Tester, Every Device)

Estimated time: 45–60 minutes. Run on every device you test. RC1 had A2 FAIL.

A1✅ PASS
First Launch & Database Creation
RC1 status: PASS
Steps
  1. Fresh install (or update): open the app.
  2. Create a database with a name and a test master password.
  3. Confirm the empty entry list is shown.
  4. Relaunch the app.
  5. Enter the master password; confirm unlock.
  6. Enter a wrong master password.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A2✅ PASS
Entries of Several Types
RC1 status: FAIL — RC1: https://internal.tracker.password-depot.de/browse/AC-639
Steps
  1. Create the following entries: password entry, credit card (PIN/CVV), identity entry, information entry, entry with a protected custom field.
  2. While typing secret fields, verify keyboard behavior.
  3. Open detail view for each entry.
  4. Edit each entry and re-save.
  5. Windows interop: create encrypted file on Windows, verify it is visible on Android (AC-639).
Expected
Result
Status: ✅ PASS
Comments:
— none —
A3✅ PASS
Folders, Search, Trash
RC1 status: PASS
Steps
  1. Create two folders.
  2. Move entries between them.
  3. Search by title, username, and URL.
  4. Delete an entry (move to trash).
  5. Restore it from the recycle bin.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A4✅ PASS
Locking
RC1 status: PASS
Steps
  1. Background the app and return quickly (within the auto-lock time).
  2. Stay away past the auto-lock time.
  3. Force-close the app from Recents.
  4. Relaunch.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A5✅ PASS
Biometric Unlock + Invalidation
RC1 status: PASS
Steps
  1. Enable Settings → Security → Biometric unlock.
  2. Lock the database.
  3. Unlock using fingerprint/face.
  4. Enroll an additional fingerprint in the Android system settings.
  5. Return to the app.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A6✅ PASS
Clipboard
RC1 status: PASS
Steps
  1. Copy a password from the detail view.
  2. Check if a countdown notification appears.
  3. Paste the password in another app.
  4. Wait 30 seconds; attempt to paste again.
  5. Try the "Clear now" button in the notification.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A7✅ PASS
Autofill in Your Daily Browser
Note: Chrome 131+ extra step required: Chrome → Settings → Autofill services → "Autofill using another service" → restart Chrome.
RC1 status: PASS
Steps
  1. Enable Settings → Autofill service.
  2. Open Settings → Autofill test; confirm the suggestion appears.
  3. Navigate to a test account login page in your browser.
  4. Verify autofill suggestion appears.
  5. Fill with Password Depot.
  6. Log in with a new credential typed manually; confirm save/update prompt appears.
  7. Negative check: navigate to a look-alike domain; confirm the entry is NOT offered.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A8✅ PASS
Autofill in One App
RC1 status: PASS
Steps
  1. Open any app with a login screen (use a test account).
  2. Trigger autofill.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A9✅ PASS
Appearance, Language, Rotation, Tablet
RC1 status: PASS
Steps
  1. Switch appearance: dark → light → system mode.
  2. Switch app language DE ↔ EN.
  3. Rotate the device while unlocked.
  4. (Tablet/foldable only) Verify the two-pane list+detail layout.
Expected
Result
Status: ✅ PASS
Comments:
— none —
A10✅ PASS
Stability & Error Visibility
What to test: Any crash, freeze, or silently swallowed error is a top report.
RC1 status: PASS
Steps
  1. If any of the above occur, open Support data immediately.
  2. Copy the version line and any listed events.
  3. File a Jira Bug with Sev-0 and attach the support data.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 3 — Focus Blocks C1–C11

Complete the blocks assigned to you, or any you have the setup for. RC1: all C1–C11 PASS.

C1✅ PASS
TOTP
Setup needed: A test account with 2FA / TOTP setup, and a reference authenticator app.
RC1 status: PASS
Steps
  1. Add a TOTP secret to a test entry using the entry editor.
  2. Use "Scan QR code" (camera or photo) to add the TOTP secret.
  3. Compare the 6-digit code with a reference authenticator for at least 3 consecutive periods.
  4. With autofill: open the 2FA field on a login page; confirm the code is offered only into the one-time-code field.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C2✅ PASS
Passkeys (Android 14+)
Setup needed: Android 14+, device screen lock enabled. Test site: https://webauthn.io
RC1 status: PASS
Steps
  1. Settings → Passkey provider → select Password Depot. Verify the row shows "Enabled".
  2. On webauthn.io: register a new passkey.
  3. Sign in with the passkey using the same database.
  4. Move the passkey entry to the trash.
  5. Attempt sign-in again → expect "No matching passkey in the database".
  6. Restore the passkey entry.
  7. Attempt sign-in again → confirm it works.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C3✅ PASS
WebDAV Sync
Setup needed: A real Nextcloud and/or Apache WebDAV server over HTTPS.
RC1 status: PASS
Steps
  1. Link the WebDAV server.
  2. Perform the initial database upload.
  3. Edit an entry on Android; sync; verify on Windows.
  4. Edit the same entry on both Android and Windows simultaneously.
  5. Sync from Android.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C4✅ PASS
Windows Interop
Setup needed: Windows Password Depot 19 and the same database accessible on both.
RC1 status: PASS
Steps
  1. Open the same .pswe file alternately in Windows PD 19 and Android.
  2. Verify that entries with umlauts/emoji, folders, attachments, TAN lists, entry history, custom icons and a second-password entry survive both directions.
  3. Set an expiry date on Android; open in Windows; confirm the date is preserved.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C5✅ PASS
Attachments
RC1 status: PASS
Steps
  1. Attach a photo (a few MB) to an entry; reopen and export it.
  2. Attach a PDF (a few MB) to an entry; reopen and export it.
  3. Attempt to attach a file over 25 MB.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C6✅ PASS
Multi-Database & Master Password Change
What to test: The app's copy of every database lives in the app's private storage. A database created "on this device" has no external file — removing it deletes the only copy.
RC1 status: PASS
Steps
  1. Create a second database; switch between both databases.
  2. Export a copy of the second database; open that file via "Open database file…".
  3. Remove THAT entry from the app — the file in Downloads must still exist — and open it again.
  4. Change the master password of a test database.
  5. Attempt to unlock with the old password.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C7✅ PASS
Backup & Restore
RC1 status: PASS
Steps
  1. Navigate to Databases & sync → Backup copies; create a backup of a test database.
  2. Make a few changes to the database.
  3. Restore an earlier backup copy.
  4. Enter a wrong password during restore; check for throttle and message.
  5. Enter the correct password; confirm restore.
  6. Attempt to restore a deliberately corrupted backup file.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C8✅ PASS
Enterprise Thin Client
Setup needed: Office test server (Enterprise Server 20).
RC1 status: PASS
Steps
  1. Open the app → "Enterprise server…" on the start screen.
  2. Enter the server address and port; log in.
  3. On first connect: verify the TLS fingerprint confirmation dialog appears.
  4. Browse and search entries on the server.
  5. Edit an entry and save.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C9✅ PASS
Enterprise Offline Copy
Setup needed: Enterprise Server 20, TCP port 25020, a database with the offline right granted.
RC1 status: PASS
Steps
  1. Sign in to the server; tap "Save offline copy…" on the database list.
  2. Enter the server password.
  3. Tap "Load databases" — confirm the TLS fingerprint once.
  4. Pick a database; confirm the copy is saved.
  5. Sign out; tap "Open offline copy" on the login screen.
  6. Create/edit an entry offline; note the waiting-changes counter.
  7. Settings → Sync… → "Send changes to the server".
Expected
Result
Status: ✅ PASS
Comments:
— none —
C10✅ PASS
Enterprise Single Sign-On (OpenID Connect / Entra ID)
Setup needed: Enterprise Server 20 with a configured OpenID Connect or Entra ID sign-in provider.
RC1 status: PASS
Steps
  1. Choose "Single sign-on (OpenID Connect / Entra ID)" in the Enterprise login; tap "Connect".
  2. Complete sign-in in the browser.
  3. Sign out; use "Sign in with a different account".
  4. Start a sign-in and cancel it in the browser.
  5. Sign in with an account the server does not know.
Expected
Result
Status: ✅ PASS
Comments:
— none —
C11✅ PASS
Hand-Over of Previous-App Offline Changes
Setup needed: Enterprise Server 20, TCP port 25020.
RC1 status: PASS
Steps
  1. Start with the previous Password Depot for Android app installed and an Enterprise database with unsent offline changes.
  2. Update to RC4; open "Import from previous app".
  3. Verify the report names the number of unsent changes.
  4. Tap "Send to the server…".
  5. Confirm the note disappears and the changes are on the server.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 4 — RC1 New Bugs Re-Test (AC-638, AC-639, AC-640, AC-646)

These are the 4 New Bugs discovered manually during RC1. Each must be re-tested on RC4.

NEW-1AC-638Sev-2✅ PASS
Migration: After setting master password on an imported key-file-only database, unlock screen fails to show password field and reports "The key file is incorrect"
Setup needed: A 19.x key-file-only database for migration.
RC1 status: OPEN (new)
Steps
  1. Import the key-file-only database from 19.x.
  2. Set a master password on the imported database.
  3. Lock the database.
  4. Attempt to unlock: verify the password field is shown.
  5. Enter the master password and unlock.
Expected
Result
Status: ✅ PASS
Comments:
— none —
NEW-2AC-639Sev-2✅ PASS
Encrypted file created on Windows client not visible on Android client
Setup needed: Windows client with the same database; Android RC4.
RC1 status: OPEN (new)
Steps
  1. On Windows, create an encrypted file entry / encrypted file in the database.
  2. Sync or open the same database on Android.
  3. Check whether the encrypted file is visible.
  4. Open it if visible.
Expected
Result
Status: ✅ PASS
Comments:
— none —
NEW-3AC-640Sev-2❌ FAIL
App crashes during Autofill prompt when reconnecting to server DB via "Use a local database instead" link
Setup needed: Enterprise Server DB; let the session expire.
RC1 status: OPEN (new) / RC-8 related
Steps
  1. Sign in to the server DB.
  2. Wait for the server session to expire (or force it).
  3. Trigger autofill in a browser / app.
  4. Tap "Use a local database instead".
  5. Verify the app navigates to local database selection (NOT server DB login).
  6. If a dialog appears, enter credentials and tap Connect — app must NOT crash.
Expected
Result
Status: ❌ FAIL
Tested device: Galaxy S22
Comments:
Reopened, crash issue is fixed, but if I use SSO to log in, save the database offline, then open the offline DB → Settings → Autofill test → click “User name” field → Fill in with password depot, the page shown in the screenshot appears. I cannot enter a password or use SSO to auto-fill. Hence reopen the issue.
NEW-4AC-646Sev-2✅ PASS
Migration: "Verify and import" button is disabled when importing multiple databases with different keyfiles/passwords
Setup needed: A v19 installation with multiple databases using different key files and passwords.
RC1 status: OPEN (new)
Steps
  1. Start the v19 → v20 (RC4) upgrade.
  2. When prompted, enter passwords and key files for all databases.
  3. After providing all required credentials, check the bottom "Verify and import" button.
  4. Tap it and complete the import.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 5 — RC1 Closed Bugs Regression (14)

These 14 bugs were closed and verified in RC1. Confirm no regression on RC4.

REG-1AC-608Sev-2✅ PASS
SSO / OpenID Connect login fails on Android client when 2FA is enabled on Enterprise Server
RC1 status: CLOSED
Steps
  1. Sign in with SSO/OpenID Connect when 2FA is enabled on Enterprise Server 20.
  2. Confirm login succeeds.
Expected
Result
Status: ✅ PASS
Comments:
— none —
REG-2AC-604Sev-2✅ PASS
Migration: key file of an imported legacy database can never be selected again - user locked out
RC1 status: CLOSED
Steps
  1. Migrate a 19.x key-file database.
  2. Verify the key file can be selected again in unlock prompts.
Expected
Result
Status: ✅ PASS
Comments:
— none —
REG-3AC-605Sev-2✅ PASS
Key-file-only databases are labelled "Also protected by a key file", contradicting the sentence below it
RC1 status: CLOSED
Steps
  1. Open a key-file-only database.
  2. Check the wording.
Expected
Result
Status: ✅ PASS
Comments:
— none —
REG-4AC-606Sev-2✅ PASS
Imported legacy databases keep their file extension and folder prefix as the database name
RC1 status: CLOSED
Steps
  1. Migrate a 19.x database with long path/extension.
  2. Check the name in the database list.
Expected
Result
Status: ✅ PASS
Comments:
— none —
REG-5AC-610Sev-2✅ PASS
Settings: "Keep autofill unlocked for..." does not mention that "Auto-lock" ends the autofill grace period earlier
RC1 status: CLOSED
Steps
  1. Open Settings → Autofill & passkeys.
  2. Check the hint text.
Expected
Result
Status: ✅ PASS
Comments:
— none —
REG-6AC-537Sev-2✅ PASS
Autofill: Autofill fails to fill TOTP when Username, Password, and TOTP are on the same page (Server DB only)
RC1 status: CLOSED (Firefox limitation)
Steps
  1. Server DB; open a page with username, password and TOTP on the same page.
  2. Trigger autofill.
Expected
Result
Status: ✅ PASS
Comments:
— none —
REG-7AC-620Sev-2✅ PASS
Autofill: Modifying username after autofill and logging in creates a new entry instead of updating existing entry
RC1 status: CLOSED
Steps
  1. Autofill username/password; change username; log in.
  2. Tap Update when prompted.
Expected
Result
Status: ✅ PASS
Comments:
— none —
REG-8AC-623Sev-2✅ PASS
Recycle Bin: Add button/option to empty or clean recycle bin
RC1 status: CLOSED
Steps
  1. Open recycle bin.
  2. Look for empty/clean action.
Expected
Result
Status: ✅ PASS
Comments:
— none —
REG-9AC-624Sev-2✅ PASS
Autofill: Autofill in Edge browser fails to detect target URL (unknown target)
RC1 status: CLOSED
Steps
  1. Open Edge; navigate to login page; trigger autofill.
Expected
Result
Status: ✅ PASS
Comments:
— none —
REG-10AC-625Sev-2✅ PASS
Server DB: TOTP field/code is not displayed in entry details view on Android client
RC1 status: CLOSED
Steps
  1. Server DB entry with TOTP; open details.
Expected
Result
Status: ✅ PASS
Comments:
— none —
REG-11AC-626Sev-2✅ PASS
Entry Details: Importance set to "High" is incorrectly displayed as "Low" on Android client
RC1 status: CLOSED
Steps
  1. Entry with Importance High; open on Android.
Expected
Result
Status: ✅ PASS
Comments:
— none —
REG-12AC-628Sev-2✅ PASS
Server DB: Redundant "Expires" field displayed in DETAILS block for Credit Card entries created via Windows Client in ES DB
RC1 status: CLOSED
Steps
  1. Credit Card entry from Windows ES DB; open on Android.
Expected
Result
Status: ✅ PASS
Comments:
— none —
REG-13AC-629Sev-2✅ PASS
Unify entry field/item names across new clients with Windows client
RC1 status: CLOSED
Steps
  1. Compare field/item labels Android vs Windows.
Expected
Result
Status: ✅ PASS
Comments:
— none —
REG-14AC-622Sev-2✅ PASS
Server DB not able to set second password on new entry or edit entry
RC1 status: CLOSED
Steps
  1. Server DB; create/edit entry; set second password.
Expected
Result
Status: ✅ PASS
Comments:
— none —

5 · Device Matrix Contribution

DimensionVariantCoveredNotes
KeyboardGboard✅
KeyboardSamsung Keyboard✅
KeyboardSwiftKey✅
BrowserChrome✅
BrowserEdge✅
BrowserFirefox✅
BrowserSamsung Internet—
Autofill styleAndroid 11+ inline chips (note which you saw)✅
Autofill styleAndroid ≤13 dropdown✅
ClipboardSamsung clipboard behavior✅
ClipboardPixel clipboard behaviorn/a
ClipboardXiaomi clipboard behaviorn/a
BiometricsFingerprint✅
BiometricsFace unlock✅
BiometricsBoth enrolled✅
OEM quirksXiaomi/HyperOS battery saver — auto-lock reliable?n/a
OEM quirksSamsung battery saver — session killed mid-edit?✅
Form factorPhone✅
Form factorTablet (≥ 600 dp)n/a
Form factorFoldablen/a
StorageFTPS / FTPES✅
StorageHiDrive✅
Migration19.x migration with key-file database✅
RC4 SmokeGoogle Play internal test track install✅

6 · Reporting Reference

Jira ProjectAndroid Client (AC)
Affects Version20.0.0
Build line20.0.0 RC4
ReleaseRC4 · Google Play submission pending
Severity 0crash · data loss · lock-out
Severity 1feature wrong or unusable
Severity 2wrong, has a workaround
Severity 3visual / text

Support data: lock the app → tap "Support data…" on the unlock screen.