Password Depot for Android — RC5 QA Test Report
Build 20.0.0 RC5 (2004) · Release Candidate 5 · Regression of 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · Generated 9/29/2026, 7:19:32 PM
1 · Environment
| Device / Android | Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14 |
|---|
| Keyboard | Samsung Keyboard 5.9.12, Gboard |
|---|
| Browser(s) | Chrome 154 |
|---|
| Build line | 20.0.0 RC5 (2004) |
|---|
| Tester | Sheva Ma |
|---|
| Date started | 2026-09-29 |
|---|
2 · Summary
| Block | Total | ✅ Pass/Fixed | ❌ Fail | 🚫 Blocked | ⏭️ Skip | 🔄 In Progress | ⬜ Pending |
|---|
| Part 0 — RC4 FAILURES Re-Test | 1 | 1 | 0 | 0 | 0 | 0 | 0 |
| Part 1 — RC4 NEW BUGS Re-Test | 2 | 2 | 0 | 0 | 0 | 0 | 0 |
| Part 2 — RC4 CLOSED BUGS Regression (11) | 11 | 8 | 0 | 0 | 0 | 3 | 0 |
| Part 3 — RC5 Smoke: Google Play Readiness | 7 | 7 | 0 | 0 | 0 | 0 | 0 |
| Part 4 — Security & MDM | 4 | 0 | 0 | 0 | 0 | 0 | 4 |
| Part 5 — RC1 Reported Bugs Re-Verification (from RC1 report) | 11 | 0 | 0 | 0 | 0 | 0 | 11 |
| Part 6 — Beta21 / RC1 Regression (R18-1 – R18-7) | 7 | 0 | 0 | 0 | 0 | 0 | 7 |
| Part 7 — Core Pass: A1–A10 (Every Tester, Every Device) | 10 | 0 | 0 | 0 | 0 | 0 | 10 |
| Part 8 — Focus Blocks C1–C11 | 11 | 0 | 0 | 0 | 0 | 0 | 11 |
| Total | 64 | 18 | 0 | 0 | 0 | 3 | 43 |
| Items tested / total | 18 / 64 |
|---|
| Pass rate (of decided items) | 100% |
|---|
| Failures | 0 |
|---|
| Blocked items | 0 |
|---|
| Reported bugs re-verified: fixed | 0 / 11 |
|---|
| Reported bugs re-verified: still broken | 0 / 11 |
|---|
| New bugs discovered (manual entry) | 2 |
|---|
| Closed bugs (verified fixed this round) | 0 |
|---|
3a · RC4 FAILURES Re-Test (0)
No RC4 failures re-tested this round. 🎉
3b · RC4 NEW BUGS Re-Test
RC4-N1AC-669Editing entry with configured TOTP does not load/mask existing setup key (shows placeholder "New setup key (Base32)") — ✅ FIXED
Verified on device: — not provided —
Comments: — none —
RC4-N2AC-671SSO connecting Server DB: closing/canceling web login disables "Connect" button permanently — ✅ FIXED
Verified on device: — not provided —
Comments: — none —
3c · RC4 CLOSED BUGS Regression (11)
RC4-C1AC-638🔄 IN PROGRESS
Migration: After setting master password on an imported key-file-only database, unlock screen fails to show password field and reports "The key file is incorrect"
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C2AC-639✅ PASS
Encrypted file & Certificate entry created on Windows client not visible on Android client
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C3AC-646🔄 IN PROGRESS
Migration: "Verify and import" button is disabled when importing multiple databases with different keyfiles/passwords
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C4AC-611✅ PASS
Second password: Saved field contents lost on next save due to unprotect/reprotect projection discarding undecrypted custom fields and U+FFFD characters
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C5AC-612✅ PASS
Document entry: Selecting file via "Choose file..." does not populate "Original path" and leaves "Save" button disabled
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C6AC-613✅ PASS
Server DB: Category field does not display dropdown / selection menu in entry editor
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C7AC-614✅ PASS
Server DB: TOTP field does not support QR code scanning in entry editor
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C8AC-615✅ PASS
OIDC SSO: passkey unlock launches PD master-password prompt after sign-out (blocks WebAuthn auth)
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C9AC-617🔄 IN PROGRESS
Sync: "Sign in with OIDC" button has no response on "Load fresh copy from the server" dialog
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C10AC-627✅ PASS
Entry: Warning message configured on Windows client does not pop up when accessing the entry on Android
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
RC4-C11AC-642✅ PASS
SSO opening offline Server DB: closing/canceling web login disables "Sign in and open" button permanently
RC4 note: Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Tested device: — not provided —
Comments: — none —
3d · RC1 Reported Bugs Re-Verification (11)
New Bugs from RC1 report (8)
REV-N1AC-620Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDAutofill: Modifying username after autofill and logging in creates a new entry instead of updating existing entry
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #1
Original device: Galaxy S22, Android 15
Original note: After autofilling username and password in Chrome, changing the username and logging in prompts to update the entry. Clicking Update creates a new entry instead of updating the existing one.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N2AC-623Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDRecycle Bin: Add button/option to empty or clean recycle bin
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #2
Original device: NA
Original note: No option to empty the entire recycle bin in the Android client.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N3AC-624Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDAutofill: Autofill in Edge browser fails to detect target URL (unknown target)
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #3
Original device: Samsung Galaxy S22
Original note: Edge on Android does not detect the target URL; "unknown target" shown; matching entry not suggested.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N4AC-625Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDServer DB: TOTP field/code is not displayed in entry details view on Android client
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #4
Original device: Galaxy S22, Pixel 10 Pro, Redmi Note 14 Pro, Tab S11
Original note: TOTP field/code not shown in entry details view for Server DB entries on Android.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N5AC-626Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDEntry Details: Importance set to "High" is incorrectly displayed as "Low" on Android client
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #5
Original device: Galaxy S22, Pixel 10 Pro, Redmi Note 14 Pro, Tab S11
Original note: Importance "High" set on Windows/Server DB is shown as "Low" on Android.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N6AC-627Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDEntry: Warning message configured on Windows client does not pop up when accessing the entry on Android
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #6
Original device: Galaxy S22, Pixel 10 Pro, Redmi Note 14 Pro, Tab S11
Original note: Warning message configured on Windows should pop up on Android before showing details/copying credentials.
RC1 note: RC1: Need to wait ES-1002 ready for testing.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N7AC-628Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDServer DB: Redundant "Expires" field displayed in DETAILS block for Credit Card entries created via Windows Client in ES DB
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #7
Original device: Galaxy S22, Pixel 10 Pro, Redmi Note 14 Pro, Tab S11
Original note: DETAILS block should not display a redundant/empty Expires field for Credit Card entries.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-N8AC-629Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDUnify entry field/item names across new clients with Windows client
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · New bug #8
Original device: Galaxy S22, Pixel 10 Pro, Redmi Note 14 Pro, Tab S11
Original note: Feature request: unify entry field/item names across new clients with Windows client.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
Closed Bugs from RC1 report (3)
REV-C1AC-440Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDAndroid Client becomes slow and laggy when database contains 20,000+ entries
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · Closed bug #1
Original device: — not provided — · Originally fixed in: 20.0.0-beta22 (1952)
Original note: Verified closed
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-C2AC-430Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDSSPI login mode - User Logon Name Format settings do not match expected behavior for Simple, Domain\sAMAccountName, and UPN modes
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · Closed bug #2
Original device: — not provided — · Originally fixed in: 20.0.0-beta22 (1952)
Original note: Verified closed.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
REV-C3AC-333Sev-2RC4: FIXEDRC5: ⬜ NOT TESTEDBetter to open a numeric keyboard when input a Service phone field
Originally reported in: 20.0.0 RC4 · RC4 QA Report · 2026-09-28 · Closed bug #3
Original device: — not provided — · Originally fixed in: 20.0.0-beta22 (1952)
Original note: Verified closed.
RC5 re-verification — device: — not provided —
RC5 re-verification comments:
— none —
3e · New Bugs Discovered (Manual Entry — this round) (2)
NEW #1AC-714Sev-2Server offline DB shows "No entry matches" and empty list in Autofill test after Server DB login and PIN unlock
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
Description:
Impact
Users cannot access autofill entries correctly on the Autofill test page when using a Server offline DB on Android.
After login and PIN unlock, the app shows no matching entries and an empty list.
NEW #2AC-717Sev-2Switching to standard user offline DB still prompts for SSO login after saving SSO offline DB
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
Description:
Impact
Users cannot log in to or open a standard user's offline database. The client stays locked in SSO authentication mode from the previously saved SSO offline DB, so users cannot switch back to standard user login.
3f · Closed Bugs (Verified Fixed — this round) (0)
No closed bugs were logged this round.
3g · Blocked Items (0)
No items were blocked this round.
4 · Detailed Results
Part 0 — RC4 FAILURES Re-Test
This is the 1 failure from the RC4 QA Report (2026-09-28, section 3b). AC-640 was reopened on RC4: the crash is fixed, but the SSO + offline DB + autofill test path still fails. Re-test carefully on RC5. This is a release blocker.
RC4-F1AC-640Sev-2✅ PASS
App crashes during Autofill prompt when reconnecting to server DB via "Use a local database instead" link
Setup needed: Enterprise Server DB; let the session expire. Also reproduce the SSO + offline DB path.
RC1 status: OPEN (new) / RC-8 related
RC4 status: FAIL — RC4: Reopened. Crash issue is fixed, but if I use SSO to log in, save the database offline, then open the offline DB → Settings → Autofill test → click "User name" field → Fill in with password depot, the page shown in the screenshot appears. I cannot enter a password or use SSO to auto-fill. Hence reopen the issue.
Steps
- Sign in to the server DB (regular server DB path).
- Wait for the server session to expire (or force it).
- Trigger autofill in a browser / app.
- Tap "Use a local database instead".
- Verify the app navigates to local database selection (NOT server DB login).
- If a dialog appears, enter credentials and tap Connect — app must NOT crash.
- SSO + offline DB path: use SSO to log in, save the database offline, open the offline DB.
- Go to Settings → Autofill test → click the "User name" field → tap "Fill in with Password Depot".
- Verify the autofill UI is usable — you can enter a password or use SSO autofill.
- Verify no error page/screenshot-like state appears instead of the autofill UI.
Expected
- Tapping "Use a local database instead" opens local database selection.
- No server DB login dialog appears unexpectedly.
- No crash when connecting.
- SSO + offline DB autofill UI is usable — password / SSO autofill works.
- No unusable error page appears.
Result
Status: ✅ PASS
Comments:
Part 1 — RC4 NEW BUGS Re-Test
These are the 2 New Bugs discovered manually during RC4 (RC4 QA Report 2026-09-28, section 3c). Each must be re-tested on RC5.
RC4-N1AC-669Sev-2✅ PASS
Editing entry with configured TOTP does not load/mask existing setup key (shows placeholder "New setup key (Base32)")
Setup needed: An entry with a valid TOTP setup key configured.
RC4 status: OPEN (new #1) — When editing an entry with an existing TOTP secret, the setup key field does not load; it shows placeholder "New setup key (Base32)". Expected: key loaded, masked by default, eye icon reveals plaintext.
Steps
- Open the entry in edit mode (Edit Entry / Properties).
- Locate the "One-time code (TOTP)" / "2FA Secret" setup key field.
- Observe the field content and the visibility toggle (eye icon).
- Click the eye icon.
- Lock and unlock; reopen the entry in edit mode; re-check the field.
Expected
- Existing TOTP setup key is loaded into the field by default.
- Key masked by default (e.g., •••••••• / ****).
- Eye icon unmasks and shows plaintext Base32 key.
- Re-opening the entry keeps the key loaded correctly.
Result
Status: ✅ PASS
Comments:
RC4-N2AC-671Sev-2✅ PASS
SSO connecting Server DB: closing/canceling web login disables "Connect" button permanently
Setup needed: Enterprise Server DB with SSO (OpenID Connect).
RC4 status: OPEN (new #2) — After canceling/closing the SSO web login, "Connect" button stays disabled; user blocked from retrying unless dialog closed/reopened or app restarted.
Steps
- Open app → Enterprise Server.
- Select Single Sign-On (OpenID Connect).
- Tap "Connect".
- When web browser / OAuth page opens, close the tab/window or navigate back.
- Return to app; check "Connect" button state.
- Try tapping "Connect" again without closing the dialog.
- Try closing and reopening the dialog, then "Connect" again.
- Try restarting the app and "Connect" again.
Expected
- After returning or canceling, "Connect" button is clickable again.
- No permanent disable.
- User can retry SSO without restarting the app.
Result
Status: ✅ PASS
Comments:
Part 2 — RC4 CLOSED BUGS Regression (11)
These 11 bugs were closed and verified in RC4 (RC4 QA Report 2026-09-28, section 3d). Confirm no regression on RC5.
RC4-C1AC-638Sev-2🔄 IN PROGRESS
Migration: After setting master password on an imported key-file-only database, unlock screen fails to show password field and reports "The key file is incorrect"
RC1 status: NEW in RC1
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
- Import key-file-only DB from 19.x.
- Set master password.
- Lock DB.
- Unlock: verify password field shown.
- Enter master password and unlock.
Expected
- Unlock shows password field; no "key file incorrect" error; unlock succeeds.
Result
Status: 🔄 IN PROGRESS
Comments:
RC4-C2AC-639Sev-2✅ PASS
Encrypted file & Certificate entry created on Windows client not visible on Android client
RC1 status: NEW in RC1
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
- On Windows, create encrypted file / certificate entry.
- Sync/open same DB on Android.
- Check entry visible.
- Open it.
Expected
- Entry visible on Android; can be opened.
Result
Status: ✅ PASS
Comments:
RC4-C3AC-646Sev-2🔄 IN PROGRESS
Migration: "Verify and import" button is disabled when importing multiple databases with different keyfiles/passwords
RC1 status: NEW in RC1
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
- Start v19 → v20 (RC5) upgrade with multiple DBs with different key files/passwords.
- Enter passwords and key files for all DBs.
- Check bottom "Verify and import" button.
- Tap it and complete import.
Expected
- Button enabled after all credentials provided; batch import succeeds.
Result
Status: 🔄 IN PROGRESS
Comments:
RC4-C4AC-611Sev-2✅ PASS
Second password: Saved field contents lost on next save due to unprotect/reprotect projection discarding undecrypted custom fields and U+FFFD characters
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
- Create/edit entry with second password and custom fields.
- Save.
- Reopen and save again.
- Verify field contents preserved.
Expected
- Second password and custom fields preserved across saves.
Result
Status: ✅ PASS
Comments:
RC4-C5AC-612Sev-2✅ PASS
Document entry: Selecting file via "Choose file..." does not populate "Original path" and leaves "Save" button disabled
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
- Create/edit Document entry.
- Tap "Choose file..."; select a file.
- Verify "Original path" populated.
- Check "Save" button state.
Expected
- Original path populated; Save button enabled.
Result
Status: ✅ PASS
Comments:
RC4-C6AC-613Sev-2✅ PASS
Server DB: Category field does not display dropdown / selection menu in entry editor
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
- Server DB; open entry editor.
- Tap Category field.
Expected
- Dropdown / selection menu appears.
Result
Status: ✅ PASS
Comments:
RC4-C7AC-614Sev-2✅ PASS
Server DB: TOTP field does not support QR code scanning in entry editor
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
- Server DB; open entry editor with TOTP.
- Use QR code scanning.
Expected
- QR code scanning works and populates the TOTP secret.
Result
Status: ✅ PASS
Comments:
RC4-C8AC-615Sev-2✅ PASS
OIDC SSO: passkey unlock launches PD master-password prompt after sign-out (blocks WebAuthn auth)
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
- Sign in via OIDC SSO.
- Sign out.
- Trigger passkey unlock.
Expected
- No PD master-password prompt; WebAuthn auth proceeds.
Result
Status: ✅ PASS
Comments:
RC4-C9AC-617Sev-2🔄 IN PROGRESS
Sync: "Sign in with OIDC" button has no response on "Load fresh copy from the server" dialog
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
- Open "Load fresh copy from the server" dialog.
- Tap "Sign in with OIDC".
Expected
- OIDC sign-in flow launches and completes.
Result
Status: 🔄 IN PROGRESS
Comments:
RC4-C10AC-627Sev-2✅ PASS
Entry: Warning message configured on Windows client does not pop up when accessing the entry on Android
RC1 status: BLOCKED in RC1
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
- Configure warning message on Windows for an entry.
- Sync/open DB on Android.
- Open that entry.
Expected
- Warning dialog appears with configured text before details.
Result
Status: ✅ PASS
Comments:
RC4-C11AC-642Sev-2✅ PASS
SSO opening offline Server DB: closing/canceling web login disables "Sign in and open" button permanently
RC4 status: CLOSED — Fixed in 20.0.0 RC4. Verified on Galaxy S22.
Steps
- Open offline copy.
- Trigger SSO sign-in ("Sign in and open").
- Close/cancel web login.
- Return to app; check button state.
Expected
- Button clickable again; no permanent disable.
Result
Status: ✅ PASS
Comments:
Part 3 — RC5 Smoke: Google Play Readiness
RC5 is the build that will go to Google Play. This is the smoke pass that must be green before submission. RC4 passed all 7; RC5 must confirm no regression.
RC-1Sev-0✅ PASS
Release build identity and Play Store readiness
Setup needed: A device with Google Play installed.
What to test: Confirm build identity, target API 36, release configuration.
RC1 status: PASS
RC4 status: PASS
Steps
- Settings → Version; confirm "20.0.0 RC5 (2004)".
- App info; confirm targetSdkVersion Android 16 (API 36).
- Not debuggable; no debug surface.
- Screenshots/recording blocked.
- Package name matches Play listing.
Expected
- Version line exact; API 36; not debuggable; screenshots blocked; package name correct.
Result
Status: ✅ PASS
Comments:
RC-2Sev-0✅ PASS
First launch on a clean device (no test data)
What to test: Empty start screen, first DB creation, first entry creation end to end.
RC1 status: PASS
RC4 status: PASS
Steps
- Uninstall previous build.
- Install RC5 from internal test track.
- Open; confirm empty start screen.
- Create DB; add entry; lock/unlock.
- Force-close and relaunch; confirm locked.
Expected
- Empty start; DB/entry creation works; force-close restarts locked.
Result
Status: ✅ PASS
Comments:
RC-4Sev-0✅ PASS
Privacy policy and data safety
What to test: Privacy policy link present, reachable, matching Data Safety declaration.
RC1 status: PASS
RC4 status: PASS
Steps
- Settings → About/Legal; confirm privacy policy link.
- Tap; confirm opens in browser.
- Confirm Data Safety declaration matches app.
Expected
- Link present and reachable; content matches; declaration accurate.
Result
Status: ✅ PASS
Comments:
RC-5Sev-1✅ PASS
Android 16 (API 36) edge-to-edge and 3-button navigation
Setup needed: Android 15/16 device with 3-button navigation.
What to test: Edge-to-edge drawing on Android 15/16 phones with 3-button navigation.
RC1 status: PASS
RC4 status: PASS
Steps
- Open app on Android 15/16 with 3-button navigation.
- Check status bar, navigation bar, keyboard.
- Open autofill window and passkey dialogs.
- Rotate.
Expected
- Edge-to-edge correct; no content hidden.
Result
Status: ✅ PASS
Comments:
RC-6Sev-1✅ PASS
All 27 languages shipped in RC5
What to test: All 27 languages listed and switching works.
RC1 status: PASS
RC4 status: PASS
Steps
- Settings → App language.
- Confirm 27 languages.
- Switch to three; confirm UI changes.
- Switch back to English.
Expected
- 27 languages listed; switching works without restart.
Result
Status: ✅ PASS
Comments:
RC-7Sev-1✅ PASS
Upgrade from a beta/RC build to RC5 with data kept
Setup needed: Device with previous build (RC4/beta22) and populated DB.
What to test: Update from previous build without losing data.
RC1 status: PASS
RC4 status: PASS
Steps
- Install previous build; create DB with entries + second-password entry.
- Update to RC5.
- Confirm DB still there and unlocks.
- Confirm entries/second-password/settings intact.
Expected
- Update installs over previous build; data kept.
Result
Status: ✅ PASS
Comments:
RC-8Sev-0✅ PASS
Crash-free cold start and warm start
What to test: Cold/warm start and autofill reconnect do not crash. RC1 failed with AC-640; RC4 passed.
RC1 status: FAIL — RC1: https://internal.tracker.password-depot.de/browse/AC-640
RC4 status: PASS
Steps
- Cold start: force-stop, then open.
- Warm start: background then foreground.
- Reboot device; open again.
- Autofill reconnect: expire server DB session, trigger autofill, tap "Use a local database instead".
- Watch for crash/ANR/freeze.
Expected
- Cold start OK; warm start clean; reboot OK; autofill reconnect no crash.
Result
Status: ✅ PASS
Comments:
Part 4 — Security & MDM
New in RC5. Covers migration throttle, MDM bans enforced at the sink (and in the autofill/passkey process from round 5), and the tablet password-reveal fix.
SEC-1Sev-1⬜ PENDING
Migration path uses the same wrong-password throttle as the unlock screen
What to test: The migration path (import from previous app) must be behind the same wrong-password throttle as the unlock screen.
Steps
- Start the migration / import from previous app flow.
- Enter the wrong password several times.
- Observe whether the same throttle as the unlock screen kicks in.
- Enter the correct password after the throttle.
Expected
- Wrong-password throttle applies to the migration path.
- Clear message shown when throttled.
- Correct password still succeeds after throttle.
Result
Status: ⬜ PENDING
Comments:
SEC-2Sev-1⬜ PENDING
MDM bans (export, cloud, autofill, clipboard) enforced at the sink
Setup needed: A device with an MDM profile that bans export / cloud / autofill / clipboard.
What to test: MDM-managed bans for export, cloud, autofill and clipboard must be enforced at the actual sink (file write, network, clipboard write, form fill), not just in the UI.
Steps
- With the MDM profile active, try to export a database / entry.
- Try to use cloud sync (WebDAV / Google Drive / HiDrive).
- Try autofill on a login page.
- Try to copy a password to the clipboard.
- Verify each is blocked at the sink (not just hidden in the UI).
Expected
- Export blocked at the file-write sink.
- Cloud blocked at the network sink.
- Autofill blocked at the fill sink.
- Clipboard blocked at the clipboard-write sink.
- No bypass via direct intent / share / external app.
Result
Status: ⬜ PENDING
Comments:
SEC-3Sev-1⬜ PENDING
MDM bans enforced in the autofill / passkey process (from round 5)
Setup needed: A device with an MDM profile that bans autofill / clipboard.
What to test: From round 5, the MDM bans are also enforced inside the separate autofill and passkey processes.
Steps
- With the MDM profile active, trigger autofill in a browser and in an app.
- Trigger a passkey registration / sign-in.
- Verify the bans are enforced inside those processes.
- Try to bypass via the autofill UI or passkey UI.
Expected
- Autofill process enforces the MDM bans.
- Passkey process enforces the MDM bans.
- No bypass from the independent process.
Result
Status: ⬜ PENDING
Comments:
SEC-4Sev-1⬜ PENDING
Tablet: revealing a password no longer wanders to the next entry when selection changes
Setup needed: A tablet / foldable with the two-pane layout.
What to test: On tablets (two-pane list+detail), after revealing a password, changing the selection must not carry the revealed plaintext to the next entry.
Steps
- Open entry A in the detail pane.
- Reveal the password for A.
- Select entry B in the list.
- Verify B does not show A's plaintext.
- Select back A; verify A's reveal state is correct.
- Rotate / search / filter / scroll; verify no plaintext leaks.
- Lock and unlock; verify reveal state is reset.
Expected
- Revealed password is bound to its entry.
- Changing selection does not carry plaintext to another entry.
- Rotation/search/filter/scroll do not leak.
- Lock/unlock resets reveal state.
Result
Status: ⬜ PENDING
Comments:
Part 6 — Beta21 / RC1 Regression (R18-1 – R18-7)
These bugs were reported in earlier rounds. R18-5 was FAIL in RC1 and is still In Progress in RC4 — re-test carefully.
R18-1AC-604Sev-0⬜ PENDING
Key file of the old app — now visible in every key-file prompt
Setup needed: A real 19.x installation with a key-file database.
RC1 status: PASS
RC4 status: PASS
Steps
- Install 19.x; create/protect DB with key file.
- Update to RC5; open takeover flow.
- Unlock screen → "Choose key file…".
- Verify old app key files listed.
- Pick correct one; unlock.
- Repeat in autofill window and passkey dialog.
- Change master password and restore.
Expected
- Old key files listed in every key-file prompt; chosen one read for that unlock only.
Result
Status: ⬜ PENDING
Comments:
R18-2AC-605Sev-3⬜ PENDING
Key-file wording: "Protected with" vs "Additionally protected with"
RC1 status: PASS
RC4 status: PASS
Steps
- Open key-file-only DB; check wording.
- Open password+key-file DB; check wording in same three places.
Expected
- Correct wording in both cases.
Result
Status: ⬜ PENDING
Comments:
R18-3AC-606Sev-3⬜ PENDING
Names after the takeover
Setup needed: A real 19.x migration.
RC1 status: PASS
RC4 status: PASS
Steps
- Migrate DB from 19.x with long path and extension.
- Check name in DB list.
- Create backup copy; check name.
- Open DB; check header.
Expected
- DB name is file name without folder/extension; backup copies named "<name> (backup copy n)".
Result
Status: ⬜ PENDING
Comments:
R18-4AC-607Sev-3⬜ PENDING
Takeover report lists skipped settings by name
Setup needed: A real 19.x installation with an invalid setting.
RC1 status: PASS
RC4 status: PASS
Steps
- Migrate from 19.x with at least one invalid setting.
- Open takeover report.
Expected
- Skipped settings listed by name.
Result
Status: ⬜ PENDING
Comments:
R18-5AC-609Sev-2⬜ PENDING
WebDAV address with "#" gets its own message
Setup needed: HiDrive account (or similar WebDAV address with "#").
RC1 status: FAIL — RC1: after entering username, URL goes to .../users/<name>/…/ but deletes database.pswe at the end. RC4: still In Progress.
RC4 status: IN PROGRESS
Steps
- Open "Open from cloud…" / "Storage location & sync".
- Paste browser address of HiDrive web interface (contains "#").
- Observe message.
- After entering username, verify "database.pswe" is NOT stripped.
Expected
- Specific message says what to enter instead.
- database.pswe preserved at end of URL.
Result
Status: ⬜ PENDING
Comments:
R18-6AC-610Sev-3⬜ PENDING
Autofill hint names the app's auto-lock value
RC1 status: PASS
RC4 status: PASS
Steps
- Set app auto-lock shorter than reuse window.
- Settings → Autofill & passkeys; find "keep unlocked for …" hint.
Expected
- Hint names auto-lock and shows its value.
Result
Status: ⬜ PENDING
Comments:
R18-7AC-537 / AC-608Sev-1⬜ PENDING
Enterprise Server: one-time codes and 2FA against Server 20
Setup needed: Enterprise Server 20 (only).
RC1 status: PASS
RC4 status: PASS
Steps
- Sign in to Enterprise Server 20.
- Trigger autofill on a site matching a server entry with one-time code.
- Verify username, password and current one-time code filled.
- Trigger 2FA failure; observe exact reason.
Expected
- Autofill fills username/password/one-time code; 2FA failures report exact reason.
Result
Status: ⬜ PENDING
Comments:
Part 7 — Core Pass: A1–A10 (Every Tester, Every Device)
Estimated time: 45–60 minutes. Run on every device you test. RC1 had A2 FAIL; RC4 passed.
A1⬜ PENDING
First Launch & Database Creation
RC1 status: PASS
RC4 status: PASS
Steps
- Fresh install (or update): open app.
- Create DB with name and test master password.
- Confirm empty entry list.
- Relaunch.
- Enter master password; confirm unlock.
- Enter wrong master password.
Expected
- Empty list; after relaunch locked; correct password unlocks; wrong password clear error.
Result
Status: ⬜ PENDING
Comments:
A2⬜ PENDING
Entries of Several Types
RC1 status: FAIL — RC1: https://internal.tracker.password-depot.de/browse/AC-639
RC4 status: PASS
Steps
- Create password entry, credit card (PIN/CVV), identity, information, protected custom field.
- While typing secret fields, check keyboard.
- Open detail view for each.
- Edit each and re-save.
- Windows interop: create encrypted file on Windows, verify visible on Android.
Expected
- Secret fields use password keyboard; detail view readable; nothing lost after edit; encrypted file visible on Android.
Result
Status: ⬜ PENDING
Comments:
A3⬜ PENDING
Folders, Search, Trash
RC1 status: PASS
RC4 status: PASS
Steps
- Create two folders.
- Move entries.
- Search by title, username, URL.
- Delete entry (move to trash).
- Restore from recycle bin.
Expected
- All operations complete; restored entry in original location.
Result
Status: ⬜ PENDING
Comments:
A4⬜ PENDING
Locking
RC1 status: PASS
RC4 status: PASS
Steps
- Background and return quickly.
- Stay away past auto-lock.
- Force-close from Recents.
- Relaunch.
Expected
- Quick background stays open; after timeout locked; after force-close next start locked.
Result
Status: ⬜ PENDING
Comments:
A5⬜ PENDING
Biometric Unlock + Invalidation
RC1 status: PASS
RC4 status: PASS
Steps
- Enable Settings → Security → Biometric unlock.
- Lock DB.
- Unlock with fingerprint/face.
- Enroll additional fingerprint in Android settings.
- Return to app.
Expected
- Biometric unlock works; after new fingerprint app refuses biometrics with explanation; can re-enable.
Result
Status: ⬜ PENDING
Comments:
A6⬜ PENDING
Clipboard
RC1 status: PASS
RC4 status: PASS
Steps
- Copy password from detail view.
- Check countdown notification.
- Paste in another app.
- Wait 30s; attempt paste again.
- Try "Clear now".
Expected
- Countdown appears; paste within 30s; after 30s no paste; "Clear now" immediate.
Result
Status: ⬜ PENDING
Comments:
A7⬜ PENDING
Autofill in Your Daily Browser
Note: Chrome 131+ extra step: Chrome → Settings → Autofill services → "Autofill using another service" → restart Chrome.
RC1 status: PASS
RC4 status: PASS
Steps
- Enable Settings → Autofill service.
- Settings → Autofill test; confirm suggestion.
- Navigate to test login page.
- Verify suggestion.
- Fill with Password Depot.
- Log in with new credential typed manually; confirm save/update prompt.
- Negative check: look-alike domain; entry NOT offered.
Expected
- Suggestion on matching domain; save/update works; no suggestion for non-matching.
Result
Status: ⬜ PENDING
Comments:
A8⬜ PENDING
Autofill in One App
RC1 status: PASS
RC4 status: PASS
Steps
- Open any app with login screen (test account).
- Trigger autofill.
Expected
- Autofill works or cleanly offers nothing — no crash, no wrong entry.
Result
Status: ⬜ PENDING
Comments:
A9⬜ PENDING
Appearance, Language, Rotation, Tablet
RC1 status: PASS
RC4 status: PASS
Steps
- Switch appearance dark → light → system.
- Switch app language DE ↔ EN.
- Rotate device while unlocked.
- (Tablet/foldable) Verify two-pane layout.
Expected
- Switches work without restart; rotation preserves state; two-pane correct on tablets.
Result
Status: ⬜ PENDING
Comments:
A10⬜ PENDING
Stability & Error Visibility
What to test: Any crash, freeze, or silently swallowed error is a top report.
RC1 status: PASS
RC4 status: PASS
Steps
- If any occur, open Support data immediately.
- Copy version line and events.
- File Jira Bug Sev-0 with support data.
Expected
- No crashes, freezes, or silently swallowed errors.
Result
Status: ⬜ PENDING
Comments:
Part 8 — Focus Blocks C1–C11
Complete the blocks assigned to you, or any you have the setup for. RC1 and RC4: all C1–C11 PASS.
C1⬜ PENDING
TOTP
Setup needed: A test account with 2FA/TOTP and a reference authenticator app.
RC1 status: PASS
RC4 status: PASS
Steps
- Add TOTP secret via entry editor.
- Use "Scan QR code" (camera/photo).
- Compare 6-digit code with reference authenticator for ≥3 periods.
- With autofill: confirm code offered only into one-time-code field.
Expected
- Codes match for ≥3 periods; code offered only into OTP fields.
Result
Status: ⬜ PENDING
Comments:
C2⬜ PENDING
Passkeys (Android 14+)
Setup needed: Android 14+, screen lock enabled. Test site: https://webauthn.io
RC1 status: PASS
RC4 status: PASS
Steps
- Settings → Passkey provider → Password Depot; verify "Enabled".
- Register a new passkey on webauthn.io.
- Sign in with the passkey.
- Move passkey entry to trash.
- Attempt sign-in → expect "No matching passkey".
- Restore passkey entry.
- Attempt sign-in again → works.
Expected
- All steps behave as described.
Result
Status: ⬜ PENDING
Comments:
C3⬜ PENDING
WebDAV Sync
Setup needed: A real Nextcloud and/or Apache WebDAV server over HTTPS.
RC1 status: PASS
RC4 status: PASS
Steps
- Link WebDAV server.
- Initial DB upload.
- Edit entry on Android; sync; verify on Windows.
- Edit same entry on both simultaneously.
- Sync from Android.
Expected
- Initial upload succeeds; concurrent edit → conflicted copy on Android.
Result
Status: ⬜ PENDING
Comments:
C4⬜ PENDING
Windows Interop
Setup needed: Windows Password Depot 19 and same DB accessible on both.
RC1 status: PASS
RC4 status: PASS
Steps
- Open same .pswe alternately in Windows PD 19 and Android.
- Verify umlauts/emoji, folders, attachments, TAN lists, entry history, custom icons, second-password entry survive both directions.
- Set expiry date on Android; open in Windows; confirm date preserved.
Expected
- All content survives both directions unchanged.
Result
Status: ⬜ PENDING
Comments:
C5⬜ PENDING
Attachments
RC1 status: PASS
RC4 status: PASS
Steps
- Attach photo (few MB); reopen and export.
- Attach PDF (few MB); reopen and export.
- Attempt to attach file over 25 MB.
Expected
- Photo/PDF attach, export, open correctly; >25 MB refused with clear message, no crash.
Result
Status: ⬜ PENDING
Comments:
C6⬜ PENDING
Multi-Database & Master Password Change
What to test: App copy of every DB lives in app private storage; "on this device" DB has no external file.
RC1 status: PASS
RC4 status: PASS
Steps
- Create second DB; switch between both.
- Export copy; open via "Open database file…".
- Remove THAT entry from app — file in Downloads must still exist — and open again.
- Change master password of test DB.
- Attempt unlock with old password.
Expected
- Switching works; "Remove from app" does not delete external file; old password rejected.
Result
Status: ⬜ PENDING
Comments:
C7⬜ PENDING
Backup & Restore
RC1 status: PASS
RC4 status: PASS
Steps
- Databases & sync → Backup copies; create backup.
- Make changes.
- Restore earlier backup.
- Wrong password during restore; check throttle and message.
- Correct password; confirm restore.
- Attempt restore of corrupted backup.
Expected
- Correct password restores; current state saved before restore; wrong password throttle + message; corrupted backup refused, active DB untouched.
Result
Status: ⬜ PENDING
Comments:
C8⬜ PENDING
Enterprise Thin Client
Setup needed: Office test server (Enterprise Server 20).
RC1 status: PASS
RC4 status: PASS
Steps
- App → "Enterprise server…".
- Enter address/port; log in.
- First connect: verify TLS fingerprint dialog.
- Browse and search entries.
- Edit entry and save.
Expected
- TLS fingerprint dialog first connect; login succeeds; browse/search/edit work.
Result
Status: ⬜ PENDING
Comments:
C9⬜ PENDING
Enterprise Offline Copy
Setup needed: Enterprise Server 20, TCP port 25020, DB with offline right granted.
RC1 status: PASS
RC4 status: PASS
Steps
- Sign in; tap "Save offline copy…".
- Enter server password.
- Tap "Load databases" — confirm TLS fingerprint once.
- Pick DB; confirm copy saved.
- Sign out; tap "Open offline copy".
- Create/edit entry offline; note waiting-changes counter.
- Settings → Sync… → "Send changes to the server".
Expected
- All steps behave as described.
Result
Status: ⬜ PENDING
Comments:
C10⬜ PENDING
Enterprise Single Sign-On (OpenID Connect / Entra ID)
Setup needed: Enterprise Server 20 with configured OIDC or Entra ID provider.
RC1 status: PASS
RC4 status: PASS
Steps
- Choose "Single sign-on (OpenID Connect / Entra ID)"; tap "Connect".
- Complete sign-in in browser.
- Sign out; use "Sign in with a different account".
- Start sign-in and cancel in browser.
- Sign in with account server does not know.
Expected
- All scenarios behave as described.
Result
Status: ⬜ PENDING
Comments:
C11⬜ PENDING
Hand-Over of Previous-App Offline Changes
Setup needed: Enterprise Server 20, TCP port 25020.
RC1 status: PASS
RC4 status: PASS
Steps
- Start with previous Password Depot for Android installed and Enterprise DB with unsent offline changes.
- Update to RC5; open "Import from previous app".
- Verify report names number of unsent changes.
- Tap "Send to the server…".
- Confirm note disappears and changes on server.
Expected
- All steps behave as described.
Result
Status: ⬜ PENDING
Comments:
5 · Device Matrix Contribution
| Dimension | Variant | Covered | Notes |
|---|
| Keyboard | Gboard | — | |
| Keyboard | Samsung Keyboard | — | |
| Keyboard | SwiftKey | — | |
| Browser | Chrome | — | |
| Browser | Edge | — | |
| Browser | Firefox | — | |
| Browser | Samsung Internet | — | |
| Autofill style | Android 11+ inline chips | — | |
| Autofill style | Android ≤13 dropdown | — | |
| Clipboard | Samsung clipboard behavior | — | |
| Clipboard | Pixel clipboard behavior | — | |
| Clipboard | Xiaomi clipboard behavior | — | |
| Biometrics | Fingerprint | — | |
| Biometrics | Face unlock | — | |
| Biometrics | Both enrolled | — | |
| OEM quirks | Xiaomi/HyperOS battery saver — auto-lock reliable? | — | |
| OEM quirks | Samsung battery saver — session killed mid-edit? | — | |
| Form factor | Phone | — | |
| Form factor | Tablet (≥ 600 dp) | — | |
| Form factor | Foldable | — | |
| Storage | FTPS / FTPES | — | |
| Storage | HiDrive | — | |
| Migration | 19.x migration with key-file database | — | |
| RC5 Smoke | Google Play internal test track install | — | |
6 · Reporting Reference
| Jira Project | Android Client (AC) |
|---|
| Affects Version | 20.0.0 |
|---|
| Build line | 20.0.0 RC5 (2004) |
|---|
| Release | RC5 · Google Play submission pending |
|---|
| Severity 0 | crash · data loss · lock-out |
|---|
| Severity 1 | feature wrong or unusable |
|---|
| Severity 2 | wrong, has a workaround |
|---|
| Severity 3 | visual / text |
|---|
Support data: lock the app → tap "Support data…" on the unlock screen.