Password Depot for Android — RC5 QA Test Report

Build 20.0.0 RC5 (2004) · Release Candidate 5 · Regression of 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · Generated 9/29/2026, 7:19:32 PM

1 · Environment

Device / AndroidPhone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
KeyboardSamsung Keyboard 5.9.12, Gboard
Browser(s)Chrome 154
Build line20.0.0 RC5 (2004)
TesterSheva Ma
Date started2026-09-29

2 · Summary

BlockTotal✅ Pass/Fixed❌ Fail🚫 Blocked⏭️ Skip🔄 In Progress⬜ Pending
Part 0 — RC4 FAILURES Re-Test1100000
Part 1 — RC4 NEW BUGS Re-Test2200000
Part 2 — RC4 CLOSED BUGS Regression (11)11800030
Part 3 — RC5 Smoke: Google Play Readiness7700000
Part 4 — Security & MDM4000004
Part 5 — RC1 Reported Bugs Re-Verification (from RC1 report)110000011
Part 6 — Beta21 / RC1 Regression (R18-1 – R18-7)7000007
Part 7 — Core Pass: A1–A10 (Every Tester, Every Device)100000010
Part 8 — Focus Blocks C1–C11110000011
Total6418000343
Items tested / total18 / 64
Pass rate (of decided items)100%
Failures0
Blocked items0
Reported bugs re-verified: fixed0 / 11
Reported bugs re-verified: still broken0 / 11
New bugs discovered (manual entry)2
Closed bugs (verified fixed this round)0

3a · RC4 FAILURES Re-Test (0)

No RC4 failures re-tested this round. 🎉

3b · RC4 NEW BUGS Re-Test

RC4-N1AC-669Editing entry with configured TOTP does not load/mask existing setup key (shows placeholder "New setup key (Base32)") — ✅ FIXED
Verified on device: — not provided —
Comments: — none —
RC4-N2AC-671SSO connecting Server DB: closing/canceling web login disables "Connect" button permanently — ✅ FIXED
Verified on device: — not provided —
Comments: — none —

3c · RC4 CLOSED BUGS Regression (11)

RC4-C1AC-638🔄 IN PROGRESS
Migration: After setting master password on an imported key-file-only database, unlock screen fails to show password field and reports "The key file is incorrect"
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C2AC-639✅ PASS
Encrypted file & Certificate entry created on Windows client not visible on Android client
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C3AC-646🔄 IN PROGRESS
Migration: "Verify and import" button is disabled when importing multiple databases with different keyfiles/passwords
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C4AC-611✅ PASS
Second password: Saved field contents lost on next save due to unprotect/reprotect projection discarding undecrypted custom fields and U+FFFD characters
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C5AC-612✅ PASS
Document entry: Selecting file via "Choose file..." does not populate "Original path" and leaves "Save" button disabled
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C6AC-613✅ PASS
Server DB: Category field does not display dropdown / selection menu in entry editor
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C7AC-614✅ PASS
Server DB: TOTP field does not support QR code scanning in entry editor
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C8AC-615✅ PASS
OIDC SSO: passkey unlock launches PD master-password prompt after sign-out (blocks WebAuthn auth)
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C9AC-617🔄 IN PROGRESS
Sync: "Sign in with OIDC" button has no response on "Load fresh copy from the server" dialog
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C10AC-627✅ PASS
Entry: Warning message configured on Windows client does not pop up when accessing the entry on Android
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C11AC-642✅ PASS
SSO opening offline Server DB: closing/canceling web login disables "Sign in and open" button permanently
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —

3d · RC1 Reported Bugs Re-Verification (11)

New Bugs from RC1 report (8)

REV-N1AC-620Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDAutofill: Modifying username after autofill and logging in creates a new entry instead of updating existing entry
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #1
Original device: Galaxy S22, Android 15
Original note: After autofilling username and password in Chrome, changing the username and logging in prompts to update the entry. Clicking Update creates a new entry instead of updating the existing one.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N2AC-623Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDRecycle Bin: Add button/option to empty or clean recycle bin
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #2
Original device: NA
Original note: No option to empty the entire recycle bin in the Android client.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N3AC-624Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDAutofill: Autofill in Edge browser fails to detect target URL (unknown target)
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #3
Original device: Samsung Galaxy S22
Original note: Edge on Android does not detect the target URL; "unknown target" shown; matching entry not suggested.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N4AC-625Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDServer DB: TOTP field/code is not displayed in entry details view on Android client
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #4
Original device: Galaxy S22, Pixel 10 Pro, Redmi Note 14 Pro, Tab S11
Original note: TOTP field/code not shown in entry details view for Server DB entries on Android.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N5AC-626Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDEntry Details: Importance set to "High" is incorrectly displayed as "Low" on Android client
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #5
Original device: Galaxy S22, Pixel 10 Pro, Redmi Note 14 Pro, Tab S11
Original note: Importance "High" set on Windows/Server DB is shown as "Low" on Android.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N6AC-627Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDEntry: Warning message configured on Windows client does not pop up when accessing the entry on Android
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #6
Original device: Galaxy S22, Pixel 10 Pro, Redmi Note 14 Pro, Tab S11
Original note: Warning message configured on Windows should pop up on Android before showing details/copying credentials.
RC1 note: RC1: Need to wait ES-1002 ready for testing.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N7AC-628Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDServer DB: Redundant "Expires" field displayed in DETAILS block for Credit Card entries created via Windows Client in ES DB
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #7
Original device: Galaxy S22, Pixel 10 Pro, Redmi Note 14 Pro, Tab S11
Original note: DETAILS block should not display a redundant/empty Expires field for Credit Card entries.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N8AC-629Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDUnify entry field/item names across new clients with Windows client
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #8
Original device: Galaxy S22, Pixel 10 Pro, Redmi Note 14 Pro, Tab S11
Original note: Feature request: unify entry field/item names across new clients with Windows client.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —

Closed Bugs from RC1 report (3)

REV-C1AC-440Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDAndroid Client becomes slow and laggy when database contains 20,000+ entries
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · Closed bug #1
Original device: — not provided — · Originally fixed in: 20.0.0-beta22 (1952)
Original note: Verified closed
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-C2AC-430Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDSSPI login mode - User Logon Name Format settings do not match expected behavior for Simple, Domain\sAMAccountName, and UPN modes
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · Closed bug #2
Original device: — not provided — · Originally fixed in: 20.0.0-beta22 (1952)
Original note: Verified closed.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-C3AC-333Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDBetter to open a numeric keyboard when input a Service phone field
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · Closed bug #3
Original device: — not provided — · Originally fixed in: 20.0.0-beta22 (1952)
Original note: Verified closed.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —

3e · New Bugs Discovered (Manual Entry — this round) (2)

NEW #1AC-714Sev-2Server offline DB shows "No entry matches" and empty list in Autofill test after Server DB login and PIN unlock
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
Description:
Impact
Users cannot access autofill entries correctly on the Autofill test page when using a Server offline DB on Android.
After login and PIN unlock, the app shows no matching entries and an empty list.
NEW #2AC-717Sev-2Switching to standard user offline DB still prompts for SSO login after saving SSO offline DB
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
Description:
Impact
Users cannot log in to or open a standard user's offline database. The client stays locked in SSO authentication mode from the previously saved SSO offline DB, so users cannot switch back to standard user login.

3f · Closed Bugs (Verified Fixed — this round) (0)

No closed bugs were logged this round.

3g · Blocked Items (0)

No items were blocked this round.

4 · Detailed Results

Part 0 — RC4 FAILURES Re-Test

This is the 1 failure from the RC4 QA Report (2026-09-28, section 3b). AC-640 was reopened on RC4: the crash is fixed, but the SSO + offline DB + autofill test path still fails. Re-test carefully on RC5. This is a release blocker.

RC4-F1AC-640Sev-2✅ PASS
App crashes during Autofill prompt when reconnecting to server DB via "Use a local database instead" link
Setup needed: Enterprise Server DB; let the session expire. Also reproduce the SSO + offline DB path.
RC1 status: OPEN (new) / RC-8 related
RC4 status: FAIL — RC4: Reopened. Crash issue is fixed, but if I use SSO to log in, save the database offline, then open the offline DB → Settings → Autofill test → click "User name" field → Fill in with password depot, the page shown in the screenshot appears. I cannot enter a password or use SSO to auto-fill. Hence reopen the issue.
Steps
  1. Sign in to the server DB (regular server DB path).
  2. Wait for the server session to expire (or force it).
  3. Trigger autofill in a browser / app.
  4. Tap "Use a local database instead".
  5. Verify the app navigates to local database selection (NOT server DB login).
  6. If a dialog appears, enter credentials and tap Connect — app must NOT crash.
  7. SSO + offline DB path: use SSO to log in, save the database offline, open the offline DB.
  8. Go to Settings → Autofill test → click the "User name" field → tap "Fill in with Password Depot".
  9. Verify the autofill UI is usable — you can enter a password or use SSO autofill.
  10. Verify no error page/screenshot-like state appears instead of the autofill UI.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 1 — RC4 NEW BUGS Re-Test

These are the 2 New Bugs discovered manually during RC4 (RC4 QA Report 2026-09-28, section 3c). Each must be re-tested on RC5.

RC4-N1AC-669Sev-2✅ PASS
Editing entry with configured TOTP does not load/mask existing setup key (shows placeholder "New setup key (Base32)")
Setup needed: An entry with a valid TOTP setup key configured.
RC4 status: OPEN (new #1) — When editing an entry with an existing TOTP secret, the setup key field does not load; it shows placeholder "New setup key (Base32)". Expected: key loaded, masked by default, eye icon reveals plaintext.
Steps
  1. Open the entry in edit mode (Edit Entry / Properties).
  2. Locate the "One-time code (TOTP)" / "2FA Secret" setup key field.
  3. Observe the field content and the visibility toggle (eye icon).
  4. Click the eye icon.
  5. Lock and unlock; reopen the entry in edit mode; re-check the field.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC4-N2AC-671Sev-2✅ PASS
SSO connecting Server DB: closing/canceling web login disables "Connect" button permanently
Setup needed: Enterprise Server DB with SSO (OpenID Connect).
RC4 status: OPEN (new #2) — After canceling/closing the SSO web login, "Connect" button stays disabled; user blocked from retrying unless dialog closed/reopened or app restarted.
Steps
  1. Open app → Enterprise Server.
  2. Select Single Sign-On (OpenID Connect).
  3. Tap "Connect".
  4. When web browser / OAuth page opens, close the tab/window or navigate back.
  5. Return to app; check "Connect" button state.
  6. Try tapping "Connect" again without closing the dialog.
  7. Try closing and reopening the dialog, then "Connect" again.
  8. Try restarting the app and "Connect" again.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 2 — RC4 CLOSED BUGS Regression (11)

These 11 bugs were closed and verified in RC4 (RC4 QA Report 2026-09-28, section 3d). Confirm no regression on RC5.

RC4-C1AC-638Sev-2🔄 IN PROGRESS
Migration: After setting master password on an imported key-file-only database, unlock screen fails to show password field and reports "The key file is incorrect"
RC1 status: NEW in RC1
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
  1. Import key-file-only DB from 19.x.
  2. Set master password.
  3. Lock DB.
  4. Unlock: verify password field shown.
  5. Enter master password and unlock.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
RC4-C2AC-639Sev-2✅ PASS
Encrypted file & Certificate entry created on Windows client not visible on Android client
RC1 status: NEW in RC1
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
  1. On Windows, create encrypted file / certificate entry.
  2. Sync/open same DB on Android.
  3. Check entry visible.
  4. Open it.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC4-C3AC-646Sev-2🔄 IN PROGRESS
Migration: "Verify and import" button is disabled when importing multiple databases with different keyfiles/passwords
RC1 status: NEW in RC1
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
  1. Start v19 → v20 (RC5) upgrade with multiple DBs with different key files/passwords.
  2. Enter passwords and key files for all DBs.
  3. Check bottom "Verify and import" button.
  4. Tap it and complete import.
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
RC4-C4AC-611Sev-2✅ PASS
Second password: Saved field contents lost on next save due to unprotect/reprotect projection discarding undecrypted custom fields and U+FFFD characters
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
  1. Create/edit entry with second password and custom fields.
  2. Save.
  3. Reopen and save again.
  4. Verify field contents preserved.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC4-C5AC-612Sev-2✅ PASS
Document entry: Selecting file via "Choose file..." does not populate "Original path" and leaves "Save" button disabled
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
  1. Create/edit Document entry.
  2. Tap "Choose file..."; select a file.
  3. Verify "Original path" populated.
  4. Check "Save" button state.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC4-C6AC-613Sev-2✅ PASS
Server DB: Category field does not display dropdown / selection menu in entry editor
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
  1. Server DB; open entry editor.
  2. Tap Category field.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC4-C7AC-614Sev-2✅ PASS
Server DB: TOTP field does not support QR code scanning in entry editor
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
  1. Server DB; open entry editor with TOTP.
  2. Use QR code scanning.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC4-C8AC-615Sev-2✅ PASS
OIDC SSO: passkey unlock launches PD master-password prompt after sign-out (blocks WebAuthn auth)
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
  1. Sign in via OIDC SSO.
  2. Sign out.
  3. Trigger passkey unlock.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC4-C9AC-617Sev-2🔄 IN PROGRESS
Sync: "Sign in with OIDC" button has no response on "Load fresh copy from the server" dialog
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
  1. Open "Load fresh copy from the server" dialog.
  2. Tap "Sign in with OIDC".
Expected
Result
Status: 🔄 IN PROGRESS
Comments:
— none —
RC4-C10AC-627Sev-2✅ PASS
Entry: Warning message configured on Windows client does not pop up when accessing the entry on Android
RC1 status: BLOCKED in RC1
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
  1. Configure warning message on Windows for an entry.
  2. Sync/open DB on Android.
  3. Open that entry.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC4-C11AC-642Sev-2✅ PASS
SSO opening offline Server DB: closing/canceling web login disables "Sign in and open" button permanently
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
  1. Open offline copy.
  2. Trigger SSO sign-in ("Sign in and open").
  3. Close/cancel web login.
  4. Return to app; check button state.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 3 — RC5 Smoke: Google Play Readiness

RC5 is the build that will go to Google Play. This is the smoke pass that must be green before submission. RC4 passed all 7; RC5 must confirm no regression.

RC-1Sev-0✅ PASS
Release build identity and Play Store readiness
Setup needed: A device with Google Play installed.
What to test: Confirm build identity, target API 36, release configuration.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Settings → Version; confirm "20.0.0 RC5 (2004)".
  2. App info; confirm targetSdkVersion Android 16 (API 36).
  3. Not debuggable; no debug surface.
  4. Screenshots/recording blocked.
  5. Package name matches Play listing.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC-2Sev-0✅ PASS
First launch on a clean device (no test data)
What to test: Empty start screen, first DB creation, first entry creation end to end.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Uninstall previous build.
  2. Install RC5 from internal test track.
  3. Open; confirm empty start screen.
  4. Create DB; add entry; lock/unlock.
  5. Force-close and relaunch; confirm locked.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC-4Sev-0✅ PASS
Privacy policy and data safety
What to test: Privacy policy link present, reachable, matching Data Safety declaration.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Settings → About/Legal; confirm privacy policy link.
  2. Tap; confirm opens in browser.
  3. Confirm Data Safety declaration matches app.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC-5Sev-1✅ PASS
Android 16 (API 36) edge-to-edge and 3-button navigation
Setup needed: Android 15/16 device with 3-button navigation.
What to test: Edge-to-edge drawing on Android 15/16 phones with 3-button navigation.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Open app on Android 15/16 with 3-button navigation.
  2. Check status bar, navigation bar, keyboard.
  3. Open autofill window and passkey dialogs.
  4. Rotate.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC-6Sev-1✅ PASS
All 27 languages shipped in RC5
What to test: All 27 languages listed and switching works.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Settings → App language.
  2. Confirm 27 languages.
  3. Switch to three; confirm UI changes.
  4. Switch back to English.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC-7Sev-1✅ PASS
Upgrade from a beta/RC build to RC5 with data kept
Setup needed: Device with previous build (RC4/beta22) and populated DB.
What to test: Update from previous build without losing data.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Install previous build; create DB with entries + second-password entry.
  2. Update to RC5.
  3. Confirm DB still there and unlocks.
  4. Confirm entries/second-password/settings intact.
Expected
Result
Status: ✅ PASS
Comments:
— none —
RC-8Sev-0✅ PASS
Crash-free cold start and warm start
What to test: Cold/warm start and autofill reconnect do not crash. RC1 failed with AC-640; RC4 passed.
RC1 status: FAIL — RC1: https://internal.tracker.password-depot.de/browse/AC-640
RC4 status: PASS
Steps
  1. Cold start: force-stop, then open.
  2. Warm start: background then foreground.
  3. Reboot device; open again.
  4. Autofill reconnect: expire server DB session, trigger autofill, tap "Use a local database instead".
  5. Watch for crash/ANR/freeze.
Expected
Result
Status: ✅ PASS
Comments:
— none —

Part 4 — Security & MDM

New in RC5. Covers migration throttle, MDM bans enforced at the sink (and in the autofill/passkey process from round 5), and the tablet password-reveal fix.

SEC-1Sev-1⬜ PENDING
Migration path uses the same wrong-password throttle as the unlock screen
What to test: The migration path (import from previous app) must be behind the same wrong-password throttle as the unlock screen.
Steps
  1. Start the migration / import from previous app flow.
  2. Enter the wrong password several times.
  3. Observe whether the same throttle as the unlock screen kicks in.
  4. Enter the correct password after the throttle.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
SEC-2Sev-1⬜ PENDING
MDM bans (export, cloud, autofill, clipboard) enforced at the sink
Setup needed: A device with an MDM profile that bans export / cloud / autofill / clipboard.
What to test: MDM-managed bans for export, cloud, autofill and clipboard must be enforced at the actual sink (file write, network, clipboard write, form fill), not just in the UI.
Steps
  1. With the MDM profile active, try to export a database / entry.
  2. Try to use cloud sync (WebDAV / Google Drive / HiDrive).
  3. Try autofill on a login page.
  4. Try to copy a password to the clipboard.
  5. Verify each is blocked at the sink (not just hidden in the UI).
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
SEC-3Sev-1⬜ PENDING
MDM bans enforced in the autofill / passkey process (from round 5)
Setup needed: A device with an MDM profile that bans autofill / clipboard.
What to test: From round 5, the MDM bans are also enforced inside the separate autofill and passkey processes.
Steps
  1. With the MDM profile active, trigger autofill in a browser and in an app.
  2. Trigger a passkey registration / sign-in.
  3. Verify the bans are enforced inside those processes.
  4. Try to bypass via the autofill UI or passkey UI.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
SEC-4Sev-1⬜ PENDING
Tablet: revealing a password no longer wanders to the next entry when selection changes
Setup needed: A tablet / foldable with the two-pane layout.
What to test: On tablets (two-pane list+detail), after revealing a password, changing the selection must not carry the revealed plaintext to the next entry.
Steps
  1. Open entry A in the detail pane.
  2. Reveal the password for A.
  3. Select entry B in the list.
  4. Verify B does not show A's plaintext.
  5. Select back A; verify A's reveal state is correct.
  6. Rotate / search / filter / scroll; verify no plaintext leaks.
  7. Lock and unlock; verify reveal state is reset.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —

Part 6 — Beta21 / RC1 Regression (R18-1 – R18-7)

These bugs were reported in earlier rounds. R18-5 was FAIL in RC1 and is still In Progress in RC4 — re-test carefully.

R18-1AC-604Sev-0⬜ PENDING
Key file of the old app — now visible in every key-file prompt
Setup needed: A real 19.x installation with a key-file database.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Install 19.x; create/protect DB with key file.
  2. Update to RC5; open takeover flow.
  3. Unlock screen → "Choose key file…".
  4. Verify old app key files listed.
  5. Pick correct one; unlock.
  6. Repeat in autofill window and passkey dialog.
  7. Change master password and restore.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
R18-2AC-605Sev-3⬜ PENDING
Key-file wording: "Protected with" vs "Additionally protected with"
RC1 status: PASS
RC4 status: PASS
Steps
  1. Open key-file-only DB; check wording.
  2. Open password+key-file DB; check wording in same three places.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
R18-3AC-606Sev-3⬜ PENDING
Names after the takeover
Setup needed: A real 19.x migration.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Migrate DB from 19.x with long path and extension.
  2. Check name in DB list.
  3. Create backup copy; check name.
  4. Open DB; check header.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
R18-4AC-607Sev-3⬜ PENDING
Takeover report lists skipped settings by name
Setup needed: A real 19.x installation with an invalid setting.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Migrate from 19.x with at least one invalid setting.
  2. Open takeover report.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
R18-5AC-609Sev-2⬜ PENDING
WebDAV address with "#" gets its own message
Setup needed: HiDrive account (or similar WebDAV address with "#").
RC1 status: FAIL — RC1: after entering username, URL goes to .../users/<name>/…/ but deletes database.pswe at the end. RC4: still In Progress.
RC4 status: IN PROGRESS
Steps
  1. Open "Open from cloud…" / "Storage location & sync".
  2. Paste browser address of HiDrive web interface (contains "#").
  3. Observe message.
  4. After entering username, verify "database.pswe" is NOT stripped.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
R18-6AC-610Sev-3⬜ PENDING
Autofill hint names the app's auto-lock value
RC1 status: PASS
RC4 status: PASS
Steps
  1. Set app auto-lock shorter than reuse window.
  2. Settings → Autofill & passkeys; find "keep unlocked for …" hint.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
R18-7AC-537 / AC-608Sev-1⬜ PENDING
Enterprise Server: one-time codes and 2FA against Server 20
Setup needed: Enterprise Server 20 (only).
RC1 status: PASS
RC4 status: PASS
Steps
  1. Sign in to Enterprise Server 20.
  2. Trigger autofill on a site matching a server entry with one-time code.
  3. Verify username, password and current one-time code filled.
  4. Trigger 2FA failure; observe exact reason.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —

Part 7 — Core Pass: A1–A10 (Every Tester, Every Device)

Estimated time: 45–60 minutes. Run on every device you test. RC1 had A2 FAIL; RC4 passed.

A1⬜ PENDING
First Launch & Database Creation
RC1 status: PASS
RC4 status: PASS
Steps
  1. Fresh install (or update): open app.
  2. Create DB with name and test master password.
  3. Confirm empty entry list.
  4. Relaunch.
  5. Enter master password; confirm unlock.
  6. Enter wrong master password.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
A2⬜ PENDING
Entries of Several Types
RC1 status: FAIL — RC1: https://internal.tracker.password-depot.de/browse/AC-639
RC4 status: PASS
Steps
  1. Create password entry, credit card (PIN/CVV), identity, information, protected custom field.
  2. While typing secret fields, check keyboard.
  3. Open detail view for each.
  4. Edit each and re-save.
  5. Windows interop: create encrypted file on Windows, verify visible on Android.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
A3⬜ PENDING
Folders, Search, Trash
RC1 status: PASS
RC4 status: PASS
Steps
  1. Create two folders.
  2. Move entries.
  3. Search by title, username, URL.
  4. Delete entry (move to trash).
  5. Restore from recycle bin.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
A4⬜ PENDING
Locking
RC1 status: PASS
RC4 status: PASS
Steps
  1. Background and return quickly.
  2. Stay away past auto-lock.
  3. Force-close from Recents.
  4. Relaunch.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
A5⬜ PENDING
Biometric Unlock + Invalidation
RC1 status: PASS
RC4 status: PASS
Steps
  1. Enable Settings → Security → Biometric unlock.
  2. Lock DB.
  3. Unlock with fingerprint/face.
  4. Enroll additional fingerprint in Android settings.
  5. Return to app.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
A6⬜ PENDING
Clipboard
RC1 status: PASS
RC4 status: PASS
Steps
  1. Copy password from detail view.
  2. Check countdown notification.
  3. Paste in another app.
  4. Wait 30s; attempt paste again.
  5. Try "Clear now".
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
A7⬜ PENDING
Autofill in Your Daily Browser
Note: Chrome 131+ extra step: Chrome → Settings → Autofill services → "Autofill using another service" → restart Chrome.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Enable Settings → Autofill service.
  2. Settings → Autofill test; confirm suggestion.
  3. Navigate to test login page.
  4. Verify suggestion.
  5. Fill with Password Depot.
  6. Log in with new credential typed manually; confirm save/update prompt.
  7. Negative check: look-alike domain; entry NOT offered.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
A8⬜ PENDING
Autofill in One App
RC1 status: PASS
RC4 status: PASS
Steps
  1. Open any app with login screen (test account).
  2. Trigger autofill.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
A9⬜ PENDING
Appearance, Language, Rotation, Tablet
RC1 status: PASS
RC4 status: PASS
Steps
  1. Switch appearance dark → light → system.
  2. Switch app language DE ↔ EN.
  3. Rotate device while unlocked.
  4. (Tablet/foldable) Verify two-pane layout.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
A10⬜ PENDING
Stability & Error Visibility
What to test: Any crash, freeze, or silently swallowed error is a top report.
RC1 status: PASS
RC4 status: PASS
Steps
  1. If any occur, open Support data immediately.
  2. Copy version line and events.
  3. File Jira Bug Sev-0 with support data.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —

Part 8 — Focus Blocks C1–C11

Complete the blocks assigned to you, or any you have the setup for. RC1 and RC4: all C1–C11 PASS.

C1⬜ PENDING
TOTP
Setup needed: A test account with 2FA/TOTP and a reference authenticator app.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Add TOTP secret via entry editor.
  2. Use "Scan QR code" (camera/photo).
  3. Compare 6-digit code with reference authenticator for ≥3 periods.
  4. With autofill: confirm code offered only into one-time-code field.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
C2⬜ PENDING
Passkeys (Android 14+)
Setup needed: Android 14+, screen lock enabled. Test site: https://webauthn.io
RC1 status: PASS
RC4 status: PASS
Steps
  1. Settings → Passkey provider → Password Depot; verify "Enabled".
  2. Register a new passkey on webauthn.io.
  3. Sign in with the passkey.
  4. Move passkey entry to trash.
  5. Attempt sign-in → expect "No matching passkey".
  6. Restore passkey entry.
  7. Attempt sign-in again → works.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
C3⬜ PENDING
WebDAV Sync
Setup needed: A real Nextcloud and/or Apache WebDAV server over HTTPS.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Link WebDAV server.
  2. Initial DB upload.
  3. Edit entry on Android; sync; verify on Windows.
  4. Edit same entry on both simultaneously.
  5. Sync from Android.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
C4⬜ PENDING
Windows Interop
Setup needed: Windows Password Depot 19 and same DB accessible on both.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Open same .pswe alternately in Windows PD 19 and Android.
  2. Verify umlauts/emoji, folders, attachments, TAN lists, entry history, custom icons, second-password entry survive both directions.
  3. Set expiry date on Android; open in Windows; confirm date preserved.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
C5⬜ PENDING
Attachments
RC1 status: PASS
RC4 status: PASS
Steps
  1. Attach photo (few MB); reopen and export.
  2. Attach PDF (few MB); reopen and export.
  3. Attempt to attach file over 25 MB.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
C6⬜ PENDING
Multi-Database & Master Password Change
What to test: App copy of every DB lives in app private storage; "on this device" DB has no external file.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Create second DB; switch between both.
  2. Export copy; open via "Open database file…".
  3. Remove THAT entry from app — file in Downloads must still exist — and open again.
  4. Change master password of test DB.
  5. Attempt unlock with old password.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
C7⬜ PENDING
Backup & Restore
RC1 status: PASS
RC4 status: PASS
Steps
  1. Databases & sync → Backup copies; create backup.
  2. Make changes.
  3. Restore earlier backup.
  4. Wrong password during restore; check throttle and message.
  5. Correct password; confirm restore.
  6. Attempt restore of corrupted backup.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
C8⬜ PENDING
Enterprise Thin Client
Setup needed: Office test server (Enterprise Server 20).
RC1 status: PASS
RC4 status: PASS
Steps
  1. App → "Enterprise server…".
  2. Enter address/port; log in.
  3. First connect: verify TLS fingerprint dialog.
  4. Browse and search entries.
  5. Edit entry and save.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
C9⬜ PENDING
Enterprise Offline Copy
Setup needed: Enterprise Server 20, TCP port 25020, DB with offline right granted.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Sign in; tap "Save offline copy…".
  2. Enter server password.
  3. Tap "Load databases" — confirm TLS fingerprint once.
  4. Pick DB; confirm copy saved.
  5. Sign out; tap "Open offline copy".
  6. Create/edit entry offline; note waiting-changes counter.
  7. Settings → Sync… → "Send changes to the server".
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
C10⬜ PENDING
Enterprise Single Sign-On (OpenID Connect / Entra ID)
Setup needed: Enterprise Server 20 with configured OIDC or Entra ID provider.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Choose "Single sign-on (OpenID Connect / Entra ID)"; tap "Connect".
  2. Complete sign-in in browser.
  3. Sign out; use "Sign in with a different account".
  4. Start sign-in and cancel in browser.
  5. Sign in with account server does not know.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —
C11⬜ PENDING
Hand-Over of Previous-App Offline Changes
Setup needed: Enterprise Server 20, TCP port 25020.
RC1 status: PASS
RC4 status: PASS
Steps
  1. Start with previous Password Depot for Android installed and Enterprise DB with unsent offline changes.
  2. Update to RC5; open "Import from previous app".
  3. Verify report names number of unsent changes.
  4. Tap "Send to the server…".
  5. Confirm note disappears and changes on server.
Expected
Result
Status: ⬜ PENDING
Comments:
— none —

5 · Device Matrix Contribution

DimensionVariantCoveredNotes
KeyboardGboard—
KeyboardSamsung Keyboard—
KeyboardSwiftKey—
BrowserChrome—
BrowserEdge—
BrowserFirefox—
BrowserSamsung Internet—
Autofill styleAndroid 11+ inline chips—
Autofill styleAndroid ≤13 dropdown—
ClipboardSamsung clipboard behavior—
ClipboardPixel clipboard behavior—
ClipboardXiaomi clipboard behavior—
BiometricsFingerprint—
BiometricsFace unlock—
BiometricsBoth enrolled—
OEM quirksXiaomi/HyperOS battery saver — auto-lock reliable?—
OEM quirksSamsung battery saver — session killed mid-edit?—
Form factorPhone—
Form factorTablet (≥ 600 dp)—
Form factorFoldable—
StorageFTPS / FTPES—
StorageHiDrive—
Migration19.x migration with key-file database—
RC5 SmokeGoogle Play internal test track install—

6 · Reporting Reference

Jira ProjectAndroid Client (AC)
Affects Version20.0.0
Build line20.0.0 RC5 (2004)
ReleaseRC5 · Google Play submission pending
Severity 0crash · data loss · lock-out
Severity 1feature wrong or unusable
Severity 2wrong, has a workaround
Severity 3visual / text

Support data: lock the app → tap "Support data…" on the unlock screen.