Password Depot for Android — RC8 QA Test Report
Build 20.0.0 RC8 (2008) · Release Candidate 8 · Regression of 20.0.0 RC5 · RC5 QA Report · 2026-09-30 · Generated 10/1/2026, 7:07:29 PM
1 · Environment
| Device / Android | Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14 |
|---|
| Keyboard | Samsung Keyboard 5.9.12, Gboard |
|---|
| Browser(s) | Chrome 154 |
|---|
| Build line | 20.0.0 RC8 (2008) |
|---|
| Tester | Sheva Ma |
|---|
| Date started | 2026-10-01 |
|---|
2 · Summary
| Block | Total | ✅ Pass/Fixed | ❌ Fail | 🚫 Blocked | ⏭️ Skip | 🔄 In Progress | ⬜ Pending |
|---|
| Part 0 — RC5 NEW BUGS Re-Test | 13 | 10 | 3 | 0 | 0 | 0 | 0 |
| Part 1 — RC8 Smoke: Google Play Readiness | 7 | 7 | 0 | 0 | 0 | 0 | 0 |
| Part 2 — Security & MDM | 4 | 4 | 0 | 0 | 0 | 0 | 0 |
| Part 3 — RC1 Reported Bugs Re-Verification | 11 | 10 | 1 | 0 | 0 | 0 | 0 |
| Part 4 — Beta21 / RC1 Regression (R18-1 – R18-7) | 7 | 7 | 0 | 0 | 0 | 0 | 0 |
| Part 5 — Core Pass: A1–A10 (Every Tester, Every Device) | 10 | 10 | 0 | 0 | 0 | 0 | 0 |
| Part 6 — Focus Blocks C1–C11 | 11 | 11 | 0 | 0 | 0 | 0 | 0 |
| Total | 63 | 59 | 4 | 0 | 0 | 0 | 0 |
| Items tested / total | 63 / 63 |
|---|
| Pass rate (of decided items) | 94% |
|---|
| Failures | 4 |
|---|
| Blocked items | 0 |
|---|
| New bugs discovered (manual entry) | 2 |
|---|
| Closed bugs (verified fixed this round) | 0 |
|---|
3a · RC5 NEW BUGS Re-Test (12)
RC5-N1AC-714Sev-2❌ FAIL
Server offline DB shows "No entry matches" and empty list in Autofill test after Server DB login and PIN unlock
RC5 note: Impact: Users cannot access autofill entries correctly on the Autofill test page when using a Server offline DB on Android. After login and PIN unlock, the app shows no matching entries and an empty list.
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
Comments: Autofill test is not working correctly for offline DB now.
RC5-N2AC-717Sev-2✅ PASS
Switching to standard user offline DB still prompts for SSO login after saving SSO offline DB
RC5 note: Impact: Users cannot log in to or open a standard user’s offline database. The client stays locked in SSO authentication mode from the previously saved SSO offline DB, so users cannot switch back to standard user login.
Tested device: — not provided —
Comments: — none —
RC5-N3AC-732Sev-2✅ PASS
Server certificate confirmation prompt reappears when clicking "Load databases" in "Save offline copy" after already trusting the certificate
RC5 note: Server certificate confirmation prompt reappears when clicking "Load databases" in "Save offline copy" after already trusting the certificate.
Tested device: — not provided —
Comments: — none —
RC5-N4AC-679Sev-2✅ PASS
Home screen: Keep "Another way in" section expanded by default when databases exist
RC5 note: "Another way in" now remembers the expanded state, but it hides automatically when I create a new local DB. It should stay expanded unless the customer clicks the hide icon.
Tested device: — not provided —
Comments: — none —
RC5-N5AC-733Sev-2✅ PASS
[UX] Expand markdown toolbar items in full-screen comment editor instead of keeping them in the overflow dropdown
RC5 note: In the comment editor, when switching to full-screen mode, the toolbar retains the collapsed state from the compact/inline view, hiding many markdown/formatting actions under the ... (More) dropdown menu. Expected: toolbar adapts to viewport width in full-screen, exposing more/all formatting items directly.
Tested device: — not provided —
Comments: — none —
RC5-N6AC-734Sev-2✅ PASS
Align "Conditional access" tab in Entry editor with Windows client (UI items, warning levels & access triggers)
RC5 note: Align the Conditional access tab in the Entry editor with the Windows client. Acceptance: three severity radio options (Informational, Major, Critical); Verification text input active only when Critical is selected; support on Local DB (.pswe), offline copies, and Server DB via REST v2 ES-1002.
Tested device: — not provided —
Comments: — none —
RC5-N7AC-736Sev-2❌ FAIL
[UX/Storage] Support listing databases automatically for WebDAV, FTP, and HiDrive storage instead of requiring full file paths
RC5 note: Currently, opening/adding a DB from WebDAV, FTP/FTPS/SFTP, or HiDrive requires the full DB path/filename. Expected: log in and select from an automatically populated list of .pswe databases — consistent with Cloud Services (Dropbox, OneDrive, Google Drive) and legacy/Windows clients.
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
Comments: I still not able to proceed if I input the URL without .pswe on RC8.
RC5-N8AC-737Sev-2❌ FAIL
[UI/UX] Differentiate icons for Sidebar navigation items (Home, Entries, DB) and database storage types (Local, Cloud, Offline)
RC5 note: Currently: Home and Entries share the same icon; items under "Your Databases" reuse the same icon; all databases look identical regardless of storage backend. Expected: differentiate icons for navigation items and for storage types (Local, Cloud-synced, Offline/Cached).
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
Comments: I see RC8 20.0.0 (2008) is ready on Google Play, but I still not see this feature on it, hence reopen the it.
RC5-N9AC-738Sev-2✅ PASS
[Support Data] Copy button fails to copy logs under "From the autofill process"
RC5 note: When the "Copy" button is clicked in Support Data, only the initial logs before "From the autofill process" are copied to the clipboard. Expected: the complete Support Data content, including all content under "From the autofill process", is copied.
Tested device: — not provided —
Comments: — none —
RC5-N10AC-739Sev-2✅ PASS
[Support Data] Include app version, Android OS version, and default browser version in support data logs
RC5 note: When customers submit Support Data, key environment details (Password Depot app version, Android OS version, default browser version) are not automatically included. Expected: these are automatically included so support does not need to follow up.
Tested device: — not provided —
Comments: — none —
RC5-N11AC-698Sev-2✅ PASS
[Tablet][Enterprise] Server DB does not use two-pane (master-detail) layout unlike Local DB
RC5 note: On tablet devices, there is an inconsistent UI layout between Local/Cloud databases and Enterprise Server databases. While Local DB correctly displays a two-pane split layout (Master-Detail), Server DB fails to adopt this behavior — opening an entry in a Server DB takes up the entire screen (or single column).
Tested device: — not provided —
Comments: — none —
RC5-N12AC-704Sev-2✅ PASS
[Autofill][Android 14 Tablet] "Setup Autofill" banner remains visible after enabling autofill service and credential provider
RC5 note: On Android 14 (API 34), after enabling Password Depot as both Autofill Service and Credential Provider, the "Setup Autofill" banner does not dismiss until a fill request is triggered or the app data is re-initialized. On Android 15+ the same flow works (banner disappears onResume).
Tested device: — not provided —
Comments: — none —
RC5-N13AC-707Sev-2✅ PASS
[Security/Settings] Enable lowercase, uppercase, and numbers by default in Master Password Policy
RC5 note: In Settings > Master password policy, the current default configuration for creating a database or changing the master password is: Minimum length: 8; Lowercase OFF; Uppercase OFF; Numbers OFF; Special characters OFF. Expected: on clean install / default config with no enterprise managed settings override, the policy defaults to Minimum length 8; Lowercase ON; Uppercase ON; Numbers ON; Special characters OFF. Database creation and master password change validation must enforce these defaults unless the user changes them or enterprise server policies override them.
Tested device: — not provided —
Comments: — none —
3b · Failures on the checklist (4)
RC5-N1AC-714Server offline DB shows "No entry matches" and empty list in Autofill test after Server DB login and PIN unlock
Section: Part 0 — RC5 NEW BUGS Re-Test
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
RC5 status: OPEN (new #1) — Impact: Users cannot access autofill entries correctly on the Autofill test page when using a Server offline DB on Android. After login and PIN unlock, the app shows no matching entries and an empty list.
Comments: Autofill test is not working correctly for offline DB now.
RC5-N7AC-736[UX/Storage] Support listing databases automatically for WebDAV, FTP, and HiDrive storage instead of requiring full file paths
Section: Part 0 — RC5 NEW BUGS Re-Test
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
RC5 status: OPEN (new #7) — Currently, opening/adding a DB from WebDAV, FTP/FTPS/SFTP, or HiDrive requires the full DB path/filename. Expected: log in and select from an automatically populated list of .pswe databases — consistent with Cloud Services (Dropbox, OneDrive, Google Drive) and legacy/Windows clients.
Comments: I still not able to proceed if I input the URL without .pswe on RC8.
RC5-N8AC-737[UI/UX] Differentiate icons for Sidebar navigation items (Home, Entries, DB) and database storage types (Local, Cloud, Offline)
Section: Part 0 — RC5 NEW BUGS Re-Test
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
RC5 status: OPEN (new #8) — Currently: Home and Entries share the same icon; items under "Your Databases" reuse the same icon; all databases look identical regardless of storage backend. Expected: differentiate icons for navigation items and for storage types (Local, Cloud-synced, Offline/Cached).
Comments: I see RC8 20.0.0 (2008) is ready on Google Play, but I still not see this feature on it, hence reopen the it.
REV-N3AC-624Autofill: Autofill in Edge browser fails to detect target URL (unknown target)
Section: Part 3 — RC1 Reported Bugs Re-Verification
Tested device: App: Password Depot for Android 20.0.0 (2008) Android: 15 (API 35) Device: Google Pixel Tablet Default browser: Edge 153.0.4234.49 (com.microsoft.emmx)
RC5 status: FIXED
Comments: Reproduced this issue again on Google Pixel tablet, on Edge browser.
3c · New Bugs Discovered (Manual Entry — this round) (2)
NEW #1AC-766Sev-2Unable to access Server DB Settings on Tablet (Left rail Settings opens Local/Cloud DB settings instead)
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
Description:
Impact
When a user is logged into an Enterprise Server database on a tablet, tapping Settings in the left navigation rail opens the Local / Cloud DB settings instead of the active Server DB settings. This means users cannot access or modify Server DB settings on tablets.
Expected behaviour
The navigation rail Settings should open the active Server DB settings when connected to an Enterprise Server DB, or
A dedicated Settings / Database Properties (⚙️) icon should be available in the Server DB top bar/header, matching the phone mode implementation from AC-746.
Closing or returning from Settings should keep the user inside the active Server DB session.
Actual behaviour
The left navigation rail Settings opens the Local/Cloud DB settings.
The user cannot access Server DB Settings.
Steps to reproduce
Open Password Depot on an Android tablet, or use tablet/expanded layout mode.
Connect and log into an Enterprise Server database.
Tap the Settings icon/item in the left navigation rail.
NEW #2AC-767Sev-2[Server DB] Support adding and editing additional URLs for entries
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
Description:
Summary
The Enterprise Server (Server DB) entry editor only supports a single URL field. Users cannot add, edit, or delete additional or associated URLs for an entry.
Context
This issue occurs when using an Enterprise Server database on Android. Local/Cloud databases already support managing multiple URLs, and the Windows client has this feature as well.
Acceptance criteria
Users can add additional URLs to Server DB entries.
Users can edit additional URLs for Server DB entries.
Users can delete additional URLs for Server DB entries.
The Server DB entry editor should match the local database entry editor and Windows client feature parity.
The URL section should support a list mechanism and a “+” option for managing multiple URLs.
3d · Closed Bugs (Verified Fixed — this round) (0)
No closed bugs were logged this round.
3e · Blocked Items (0)
No items were blocked this round.
4 · Detailed Results
Part 0 — RC5 NEW BUGS Re-Test
These are the 12 New Bugs discovered in the RC5 QA Report (2026-09-30, section 3e) plus AC-698 and AC-704. Each must be re-tested on RC8. This is the highest-priority block in this checklist.
RC5-N1AC-714Sev-2❌ FAIL
Server offline DB shows "No entry matches" and empty list in Autofill test after Server DB login and PIN unlock
Setup needed: Enterprise Server DB with offline copy; Autofill test page.
RC5 status: OPEN (new #1) — Impact: Users cannot access autofill entries correctly on the Autofill test page when using a Server offline DB on Android. After login and PIN unlock, the app shows no matching entries and an empty list.
Steps
- Sign in to the Server DB and save an offline copy.
- Open the offline DB; unlock with PIN.
- Go to Settings → Autofill test.
- Check whether entries are listed / matched.
- Trigger autofill on a test login page.
Expected
- Entries are listed and matched in the Autofill test page.
- Autofill offers the matching entry — no "No entry matches" / empty list.
Result
Status: ❌ FAIL
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
Comments:
RC5-N2AC-717Sev-2✅ PASS
Switching to standard user offline DB still prompts for SSO login after saving SSO offline DB
Setup needed: A device with an SSO offline DB already saved; a standard-user offline DB available.
RC5 status: OPEN (new #2) — Impact: Users cannot log in to or open a standard user’s offline database. The client stays locked in SSO authentication mode from the previously saved SSO offline DB, so users cannot switch back to standard user login.
Steps
- Sign in with SSO and save an SSO offline DB.
- Sign out.
- Attempt to open a standard-user offline DB.
- Observe the login prompt (SSO vs standard).
- Try switching back to standard-user login.
Expected
- The client offers standard user login for the standard-user offline DB.
- No SSO prompt is forced.
Result
Status: ✅ PASS
Comments:
RC5-N3AC-732Sev-2✅ PASS
Server certificate confirmation prompt reappears when clicking "Load databases" in "Save offline copy" after already trusting the certificate
Setup needed: Enterprise Server 20; certificate previously trusted.
RC5 status: OPEN (new #3) — Server certificate confirmation prompt reappears when clicking "Load databases" in "Save offline copy" after already trusting the certificate.
Steps
- Sign in to the server and trust the certificate.
- Start "Save offline copy".
- Tap "Load databases".
- Observe whether the certificate confirmation prompt reappears.
Expected
- Certificate is remembered; no repeated confirmation prompt.
- The "Load databases" action proceeds without re-prompting.
Result
Status: ✅ PASS
Comments:
RC5-N4AC-679Sev-2✅ PASS
Home screen: Keep "Another way in" section expanded by default when databases exist
Setup needed: A device with at least one local DB.
RC5 status: OPEN (new #4) — "Another way in" now remembers the expanded state, but it hides automatically when I create a new local DB. It should stay expanded unless the customer clicks the hide icon.
Steps
- Expand the "Another way in" section on the Home screen.
- Create a new local DB.
- Return to the Home screen.
- Check whether the section is still expanded.
Expected
- "Another way in" stays expanded by default when databases exist.
- It only collapses when the user explicitly hides it.
Result
Status: ✅ PASS
Comments:
RC5-N5AC-733Sev-2✅ PASS
[UX] Expand markdown toolbar items in full-screen comment editor instead of keeping them in the overflow dropdown
Setup needed: An entry with a comment field on a device with enough horizontal space (tablet recommended).
RC5 status: OPEN (new #5) — In the comment editor, when switching to full-screen mode, the toolbar retains the collapsed state from the compact/inline view, hiding many markdown/formatting actions under the ... (More) dropdown menu. Expected: toolbar adapts to viewport width in full-screen, exposing more/all formatting items directly.
Steps
- Open the comment editor.
- Switch to full-screen mode.
- Observe the markdown/formatting toolbar.
- Compare with the compact/inline view.
Expected
- Full-screen toolbar exposes more (or all) formatting items directly.
- Overflow dropdown is minimized on large screens.
Result
Status: ✅ PASS
Comments:
RC5-N6AC-734Sev-2✅ PASS
Align "Conditional access" tab in Entry editor with Windows client (UI items, warning levels & access triggers)
Setup needed: Entry editor on Android; Windows client for reference; Server 20 with ES-1002 for server path.
RC5 status: OPEN (new #6) — Align the Conditional access tab in the Entry editor with the Windows client. Acceptance: three severity radio options (Informational, Major, Critical); Verification text input active only when Critical is selected; support on Local DB (.pswe), offline copies, and Server DB via REST v2 ES-1002.
Steps
- Open the Entry editor on Android → Conditional access tab.
- Check the severity radio options (Informational / Major / Critical).
- Select Critical; verify the Verification text input becomes active.
- Test on a Local DB (.pswe).
- Test on an offline copy.
- Test on a Server DB via REST v2 ES-1002.
Expected
- Three severity radio options present and match Windows.
- Verification text input active only when Critical is selected.
- Works on Local DB, offline copy, and Server DB (REST v2 ES-1002).
Result
Status: ✅ PASS
Comments:
RC5-N7AC-736Sev-2❌ FAIL
[UX/Storage] Support listing databases automatically for WebDAV, FTP, and HiDrive storage instead of requiring full file paths
Setup needed: A WebDAV / FTP / HiDrive account with multiple .pswe databases.
RC5 status: OPEN (new #7) — Currently, opening/adding a DB from WebDAV, FTP/FTPS/SFTP, or HiDrive requires the full DB path/filename. Expected: log in and select from an automatically populated list of .pswe databases — consistent with Cloud Services (Dropbox, OneDrive, Google Drive) and legacy/Windows clients.
Steps
- Open "Open from cloud…" / "Storage location & sync".
- Add a WebDAV / FTP / HiDrive storage location.
- Enter server address and credentials.
- Check whether the client automatically lists available .pswe databases.
- Pick one from the list.
Expected
- Available .pswe databases are listed automatically.
- User can select from the list — no full path typing required.
Result
Status: ❌ FAIL
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
Comments:
RC5-N8AC-737Sev-2❌ FAIL
[UI/UX] Differentiate icons for Sidebar navigation items (Home, Entries, DB) and database storage types (Local, Cloud, Offline)
Setup needed: A device with at least one Local, one Cloud-synced, and one Offline DB.
RC5 status: OPEN (new #8) — Currently: Home and Entries share the same icon; items under "Your Databases" reuse the same icon; all databases look identical regardless of storage backend. Expected: differentiate icons for navigation items and for storage types (Local, Cloud-synced, Offline/Cached).
Steps
- Open the navigation drawer / sidebar.
- Compare icons for Home, Entries, and the "Your Databases" list.
- Compare icons for Local, Cloud, and Offline DBs.
Expected
- Home / Entries / DB use distinct icons.
- Local / Cloud / Offline DBs are visually distinguishable.
Result
Status: ❌ FAIL
Tested device: Phone: Galaxy S22, Android 15, Tablet: T33-F11, Android 14
Comments:
RC5-N9AC-738Sev-2✅ PASS
[Support Data] Copy button fails to copy logs under "From the autofill process"
Setup needed: A device with autofill logs present.
RC5 status: OPEN (new #9) — When the "Copy" button is clicked in Support Data, only the initial logs before "From the autofill process" are copied to the clipboard. Expected: the complete Support Data content, including all content under "From the autofill process", is copied.
Steps
- Lock the app → tap "Support data…" on the unlock screen.
- Locate the "From the autofill process" section.
- Tap "Copy".
- Paste into a text editor and inspect the content.
Expected
- The full Support Data (including "From the autofill process") is copied.
- No logs after that heading are omitted.
Result
Status: ✅ PASS
Comments:
RC5-N10AC-739Sev-2✅ PASS
[Support Data] Include app version, Android OS version, and default browser version in support data logs
Setup needed: Any device.
RC5 status: OPEN (new #10) — When customers submit Support Data, key environment details (Password Depot app version, Android OS version, default browser version) are not automatically included. Expected: these are automatically included so support does not need to follow up.
Steps
- Lock the app → tap "Support data…" on the unlock screen.
- Inspect the content.
- Check for: app version, Android OS version, default browser version.
- Tap "Copy" and paste into a text editor to confirm they are present in the copied text.
Expected
- App version, Android OS version, and default browser version appear in the Support Data.
- They are also present in the copied clipboard content.
Result
Status: ✅ PASS
Comments:
RC5-N11AC-698Sev-2✅ PASS
[Tablet][Enterprise] Server DB does not use two-pane (master-detail) layout unlike Local DB
Setup needed: Android tablet (or large-screen device / emulator); both a Local DB and an Enterprise Server DB available.
RC5 status: OPEN (new #11) — On tablet devices, there is an inconsistent UI layout between Local/Cloud databases and Enterprise Server databases. While Local DB correctly displays a two-pane split layout (Master-Detail), Server DB fails to adopt this behavior — opening an entry in a Server DB takes up the entire screen (or single column).
Steps
- Launch Password Depot on an Android tablet.
- Open a Local DB (Entries tab) and tap any entry. Observe: two-pane split view (list left, detail right).
- Switch to the Enterprise tab and open an Enterprise Server DB.
- Tap any entry from the list in Server DB.
- Observe the layout.
- Rotate the device; observe whether the layout survives.
Expected
- Server DB uses the same two-pane (master-detail) layout as Local DB.
- Entry list stays visible on the left; entry details open on the right.
- Layout survives rotation.
Result
Status: ✅ PASS
Comments:
RC5-N12AC-704Sev-2✅ PASS
[Autofill][Android 14 Tablet] "Setup Autofill" banner remains visible after enabling autofill service and credential provider
Setup needed: Android 14 (API 34) tablet (e.g. T33-F11). Compare with Android 15+ (API 35, e.g. Galaxy S22).
RC5 status: OPEN (new #12) — On Android 14 (API 34), after enabling Password Depot as both Autofill Service and Credential Provider, the "Setup Autofill" banner does not dismiss until a fill request is triggered or the app data is re-initialized. On Android 15+ the same flow works (banner disappears onResume).
Steps
- Install a clean build on the Android 14 device (or clear app cache/data).
- Launch the app and log in / open a DB.
- Observe the "Setup Autofill" prompt/banner at the top of the entry list.
- Tap the "Setup Autofill" banner → system configuration screen.
- In Android System Settings: enable Password Depot under Passwords, passkeys & autofill (Autofill Service); ensure it is toggled/selected under Additional providers / Credential Manager.
- Switch back / navigate back to Password Depot.
- Observe the banner.
- Repeat on Android 15+ for comparison.
Expected
- App detects that autofill service is enabled upon onResume.
- "Setup Autofill" banner automatically disappears.
- Same behavior on Android 14 and Android 15+.
Result
Status: ✅ PASS
Comments:
RC5-N13AC-707Sev-2✅ PASS
[Security/Settings] Enable lowercase, uppercase, and numbers by default in Master Password Policy
Setup needed: Clean install (or cleared app data), no enterprise-managed settings override.
RC5 status: OPEN (new #13) — In Settings > Master password policy, the current default configuration for creating a database or changing the master password is: Minimum length: 8; Lowercase OFF; Uppercase OFF; Numbers OFF; Special characters OFF. Expected: on clean install / default config with no enterprise managed settings override, the policy defaults to Minimum length 8; Lowercase ON; Uppercase ON; Numbers ON; Special characters OFF. Database creation and master password change validation must enforce these defaults unless the user changes them or enterprise server policies override them.
Steps
- Fresh install / clear app data.
- Open Settings → Master password policy.
- Observe the default values.
- Create a new database; set a master password that violates the new defaults (e.g. all lowercase, no number).
- Try to change the master password with the same weak password.
Expected
- Min length = 8; Lowercase = ON; Uppercase = ON; Numbers = ON; Special characters = OFF (all by default on clean install).
- Database creation and master password change enforce these defaults unless the user changes them or an enterprise server policy overrides them.
Result
Status: ✅ PASS
Comments:
Part 1 — RC8 Smoke: Google Play Readiness
RC8 is the build that will go to Google Play. This is the smoke pass that must be green before submission. RC5 passed all 7; RC8 must confirm no regression.
RC-1Sev-0✅ PASS
Release build identity and Play Store readiness
Setup needed: A device with Google Play installed.
What to test: Confirm build identity, target API 36, release configuration.
RC5 status: PASS
Steps
- Settings → Version; confirm "20.0.0 RC8 (2008)".
- App info; confirm targetSdkVersion Android 16 (API 36).
- Not debuggable; no debug surface.
- Screenshots/recording blocked.
- Package name matches Play listing.
Expected
- Version line exact; API 36; not debuggable; screenshots blocked; package name correct.
Result
Status: ✅ PASS
Comments:
RC-2Sev-0✅ PASS
First launch on a clean device (no test data)
What to test: Empty start screen, first DB creation, first entry creation end to end.
RC5 status: PASS
Steps
- Uninstall previous build.
- Install RC8 from internal test track.
- Open; confirm empty start screen.
- Create DB; add entry; lock/unlock.
- Force-close and relaunch; confirm locked.
Expected
- Empty start; DB/entry creation works; force-close restarts locked.
Result
Status: ✅ PASS
Comments:
RC-4Sev-0✅ PASS
Privacy policy and data safety
What to test: Privacy policy link present, reachable, matching Data Safety declaration.
RC5 status: PASS
Steps
- Settings → About/Legal; confirm privacy policy link.
- Tap; confirm opens in browser.
- Confirm Data Safety declaration matches app.
Expected
- Link present and reachable; content matches; declaration accurate.
Result
Status: ✅ PASS
Comments:
RC-5Sev-1✅ PASS
Android 16 (API 36) edge-to-edge and 3-button navigation
Setup needed: Android 15/16 device with 3-button navigation.
What to test: Edge-to-edge drawing on Android 15/16 phones with 3-button navigation.
RC5 status: PASS
Steps
- Open app on Android 15/16 with 3-button navigation.
- Check status bar, navigation bar, keyboard.
- Open autofill window and passkey dialogs.
- Rotate.
Expected
- Edge-to-edge correct; no content hidden.
Result
Status: ✅ PASS
Comments:
RC-6Sev-1✅ PASS
All 27 languages shipped in RC8
What to test: All 27 languages listed and switching works.
RC5 status: PASS
Steps
- Settings → App language.
- Confirm 27 languages.
- Switch to three; confirm UI changes.
- Switch back to English.
Expected
- 27 languages listed; switching works without restart.
Result
Status: ✅ PASS
Comments:
RC-7Sev-1✅ PASS
Upgrade from RC5 to RC8 with data kept
Setup needed: Device with RC5 installed and a populated DB.
What to test: Update from RC5 without losing data.
RC5 status: PASS
Steps
- Install RC5; create DB with entries + second-password entry.
- Update to RC8.
- Confirm DB still there and unlocks.
- Confirm entries/second-password/settings intact.
Expected
- Update installs over RC5; data kept.
Result
Status: ✅ PASS
Comments:
RC-8Sev-0✅ PASS
Crash-free cold start and warm start
What to test: Cold/warm start and autofill reconnect do not crash. RC5 passed; RC8 must confirm.
RC5 status: PASS
Steps
- Cold start: force-stop, then open.
- Warm start: background then foreground.
- Reboot device; open again.
- Autofill reconnect: expire server DB session, trigger autofill, tap "Use a local database instead".
- Watch for crash/ANR/freeze.
Expected
- Cold start OK; warm start clean; reboot OK; autofill reconnect no crash.
Result
Status: ✅ PASS
Comments:
Part 2 — Security & MDM
Covers migration throttle, MDM bans enforced at the sink (and in the autofill/passkey process from round 5), and the tablet password-reveal fix. All PASS in RC5; confirm no regression on RC8.
SEC-1Sev-1✅ PASS
Migration path uses the same wrong-password throttle as the unlock screen
RC5 status: PASS
Steps
- Start the migration / import from previous app flow.
- Enter the wrong password several times.
- Observe whether the same throttle as the unlock screen kicks in.
- Enter the correct password after the throttle.
Expected
- Wrong-password throttle applies to the migration path.
- Clear message shown when throttled.
- Correct password still succeeds after throttle.
Result
Status: ✅ PASS
Comments:
SEC-2Sev-1✅ PASS
MDM bans (export, cloud, autofill, clipboard) enforced at the sink
Setup needed: A device with an MDM profile that bans export / cloud / autofill / clipboard.
RC5 status: PASS
Steps
- With the MDM profile active, try to export a database / entry.
- Try to use cloud sync (WebDAV / Google Drive / HiDrive).
- Try autofill on a login page.
- Try to copy a password to the clipboard.
- Verify each is blocked at the sink (not just hidden in the UI).
Expected
- Export blocked at the file-write sink.
- Cloud blocked at the network sink.
- Autofill blocked at the fill sink.
- Clipboard blocked at the clipboard-write sink.
- No bypass via direct intent / share / external app.
Result
Status: ✅ PASS
Comments:
SEC-3Sev-1✅ PASS
MDM bans enforced in the autofill / passkey process (from round 5)
Setup needed: A device with an MDM profile that bans autofill / clipboard.
RC5 status: PASS
Steps
- With the MDM profile active, trigger autofill in a browser and in an app.
- Trigger a passkey registration / sign-in.
- Verify the bans are enforced inside those processes.
- Try to bypass via the autofill UI or passkey UI.
Expected
- Autofill process enforces the MDM bans.
- Passkey process enforces the MDM bans.
- No bypass from the independent process.
Result
Status: ✅ PASS
Comments:
SEC-4Sev-1✅ PASS
Tablet: revealing a password no longer wanders to the next entry when selection changes
Setup needed: A tablet / foldable with the two-pane layout.
RC5 status: PASS
Steps
- Open entry A in the detail pane.
- Reveal the password for A.
- Select entry B in the list.
- Verify B does not show A’s plaintext.
- Select back A; verify A’s reveal state is correct.
- Rotate / search / filter / scroll; verify no plaintext leaks.
- Lock and unlock; verify reveal state is reset.
Expected
- Revealed password is bound to its entry.
- Changing selection does not carry plaintext to another entry.
- Rotation/search/filter/scroll do not leak.
- Lock/unlock resets reveal state.
Result
Status: ✅ PASS
Comments:
Part 3 — RC1 Reported Bugs Re-Verification
These are the 8 New Bugs and 3 Closed Bugs from the RC1 report. All PASS in RC4 and RC5; confirm no regression on RC8.
REV-N1AC-620Sev-2✅ PASS
Autofill: Modifying username after autofill and logging in creates a new entry instead of updating existing entry
RC5 status: FIXED
Steps
- Autofill username/password in Chrome.
- Change the username in the form.
- Log in; tap Update when prompted.
- Check: existing entry updated, no new entry created.
Expected
- Existing entry is updated; no new entry is created.
Result
Status: ✅ PASS
Comments:
REV-N2AC-623Sev-2✅ PASS
Recycle Bin: Add button/option to empty or clean recycle bin
RC5 status: FIXED
Steps
- Open the recycle bin.
- Look for an "Empty recycle bin" action.
Expected
- A button/menu option empties the whole recycle bin at once.
Result
Status: ✅ PASS
Comments:
REV-N3AC-624Sev-2❌ FAIL
Autofill: Autofill in Edge browser fails to detect target URL (unknown target)
RC5 status: FIXED
Steps
- Open Edge on Android.
- Navigate to a login page with a matching entry.
- Trigger autofill.
Expected
- Target URL detected; matching entry suggested.
Result
Status: ❌ FAIL
Tested device: App: Password Depot for Android 20.0.0 (2008) Android: 15 (API 35) Device: Google Pixel Tablet Default browser: Edge 153.0.4234.49 (com.microsoft.emmx)
Comments:
REV-N4AC-625Sev-2✅ PASS
Server DB: TOTP field/code is not displayed in entry details view on Android client
RC5 status: FIXED
Steps
- Sign in to Enterprise Server 20.
- Open an entry with a TOTP secret.
- Check the entry details view.
Expected
- TOTP field and current code displayed.
Result
Status: ✅ PASS
Comments:
REV-N5AC-626Sev-2✅ PASS
Entry Details: Importance set to "High" is incorrectly displayed as "Low" on Android client
RC5 status: FIXED
Steps
- Create/update entry with Importance = High on Windows.
- Open same entry on Android.
- Check the Importance badge.
Expected
- Importance badge reads "High".
Result
Status: ✅ PASS
Comments:
REV-N6AC-627Sev-2✅ PASS
Entry: Warning message configured on Windows client does not pop up when accessing the entry on Android
RC5 status: FIXED
Steps
- Configure warning message on Windows for an entry.
- Sync/open DB on Android.
- Open that entry.
Expected
- Warning dialog appears with configured text before details are shown.
Result
Status: ✅ PASS
Comments:
REV-N7AC-628Sev-2✅ PASS
Server DB: Redundant "Expires" field displayed in DETAILS block for Credit Card entries created via Windows Client in ES DB
RC5 status: FIXED
Steps
- Create Credit Card entry on Windows in ES DB.
- Open on Android.
- Check DETAILS for redundant Expires.
Expected
- No redundant/empty Expires field.
Result
Status: ✅ PASS
Comments:
REV-N8AC-629Sev-2✅ PASS
Unify entry field/item names across new clients with Windows client
RC5 status: FIXED
Steps
- Open a few entry types on Android.
- Compare labels with Windows client.
Expected
- Field/item names match the Windows client wording.
Result
Status: ✅ PASS
Comments:
REV-C1AC-440Sev-2✅ PASS
Android Client becomes slow and laggy when database contains 20,000+ entries
RC5 status: FIXED
Steps
- Open a DB with 20,000+ entries.
- Scroll the entry list.
- Search by title.
Expected
Result
Status: ✅ PASS
Comments:
REV-C2AC-430Sev-2✅ PASS
SSPI login mode - User Logon Name Format settings do not match expected behavior for Simple, Domain\sAMAccountName, and UPN modes
RC5 status: FIXED
Steps
- Open Enterprise login.
- Try Simple, DOMAIN\user, user@company.com.
- Sign in with each against Server 20 + AD.
Expected
- All three formats behave as expected.
Result
Status: ✅ PASS
Comments:
REV-C3AC-333Sev-2✅ PASS
Better to open a numeric keyboard when input a Service phone field
RC5 status: FIXED
Steps
- Open an entry with a Service phone field.
- Focus that field.
Expected
- A numeric keyboard opens.
Result
Status: ✅ PASS
Comments:
Part 4 — Beta21 / RC1 Regression (R18-1 – R18-7)
These bugs were reported in earlier rounds. All PASS in RC4 and RC5. Re-test on RC8.
R18-1AC-604Sev-0✅ PASS
Key file of the old app — now visible in every key-file prompt
Setup needed: A real 19.x installation with a key-file database.
RC5 status: PASS
Steps
- Install 19.x; create/protect DB with key file.
- Update to RC8; open takeover flow.
- Unlock screen → "Choose key file…".
- Verify old app key files listed.
- Pick correct one; unlock.
- Repeat in autofill window and passkey dialog.
- Change master password and restore.
Expected
- Old key files listed in every key-file prompt; chosen one read for that unlock only.
Result
Status: ✅ PASS
Comments:
R18-2AC-605Sev-3✅ PASS
Key-file wording: "Protected with" vs "Additionally protected with"
RC5 status: PASS
Steps
- Open key-file-only DB; check wording.
- Open password+key-file DB; check wording in same three places.
Expected
- Correct wording in both cases.
Result
Status: ✅ PASS
Comments:
R18-3AC-606Sev-3✅ PASS
Names after the takeover
Setup needed: A real 19.x migration.
RC5 status: PASS
Steps
- Migrate DB from 19.x with long path and extension.
- Check name in DB list.
- Create backup copy; check name.
- Open DB; check header.
Expected
- DB name is file name without folder/extension; backup copies named "<name> (backup copy n)".
Result
Status: ✅ PASS
Comments:
R18-4AC-607Sev-3✅ PASS
Takeover report lists skipped settings by name
Setup needed: A real 19.x installation with an invalid setting.
RC5 status: PASS
Steps
- Migrate from 19.x with at least one invalid setting.
- Open takeover report.
Expected
- Skipped settings listed by name.
Result
Status: ✅ PASS
Comments:
R18-5AC-609Sev-2✅ PASS
WebDAV address with "#" gets its own message
Setup needed: HiDrive account (or similar WebDAV address with "#").
RC5 status: PASS
Steps
- Open "Open from cloud…" / "Storage location & sync".
- Paste browser address of HiDrive web interface (contains "#").
- Observe message.
- After entering username, verify "database.pswe" is NOT stripped.
Expected
- Specific message says what to enter instead.
- database.pswe preserved at end of URL.
Result
Status: ✅ PASS
Comments:
R18-6AC-610Sev-3✅ PASS
Autofill hint names the app’s auto-lock value
RC5 status: PASS
Steps
- Set app auto-lock shorter than reuse window.
- Settings → Autofill & passkeys; find "keep unlocked for …" hint.
Expected
- Hint names auto-lock and shows its value.
Result
Status: ✅ PASS
Comments:
R18-7AC-537 / AC-608Sev-1✅ PASS
Enterprise Server: one-time codes and 2FA against Server 20
Setup needed: Enterprise Server 20 (only).
RC5 status: PASS
Steps
- Sign in to Enterprise Server 20.
- Trigger autofill on a site matching a server entry with one-time code.
- Verify username, password and current one-time code filled.
- Trigger 2FA failure; observe exact reason.
Expected
- Autofill fills username/password/one-time code; 2FA failures report exact reason.
Result
Status: ✅ PASS
Comments:
Part 5 — Core Pass: A1–A10 (Every Tester, Every Device)
Estimated time: 45–60 minutes. Run on every device you test. All PASS in RC1, RC4, RC5; confirm no regression on RC8.
A1✅ PASS
First Launch & Database Creation
RC5 status: PASS
Steps
- Fresh install (or update): open app.
- Create DB with name and test master password.
- Confirm empty entry list.
- Relaunch.
- Enter master password; confirm unlock.
- Enter wrong master password.
Expected
- Empty list; after relaunch locked; correct password unlocks; wrong password clear error.
Result
Status: ✅ PASS
Comments:
A2✅ PASS
Entries of Several Types
RC5 status: PASS
Steps
- Create password entry, credit card (PIN/CVV), identity, information, protected custom field.
- While typing secret fields, check keyboard.
- Open detail view for each.
- Edit each and re-save.
- Windows interop: create encrypted file on Windows, verify visible on Android.
Expected
- Secret fields use password keyboard; detail view readable; nothing lost after edit; encrypted file visible on Android.
Result
Status: ✅ PASS
Comments:
A3✅ PASS
Folders, Search, Trash
RC5 status: PASS
Steps
- Create two folders.
- Move entries.
- Search by title, username, URL.
- Delete entry (move to trash).
- Restore from recycle bin.
Expected
- All operations complete; restored entry in original location.
Result
Status: ✅ PASS
Comments:
A4✅ PASS
Locking
RC5 status: PASS
Steps
- Background and return quickly.
- Stay away past auto-lock.
- Force-close from Recents.
- Relaunch.
Expected
- Quick background stays open; after timeout locked; after force-close next start locked.
Result
Status: ✅ PASS
Comments:
A5✅ PASS
Biometric Unlock + Invalidation
RC5 status: PASS
Steps
- Enable Settings → Security → Biometric unlock.
- Lock DB.
- Unlock with fingerprint/face.
- Enroll additional fingerprint in Android settings.
- Return to app.
Expected
- Biometric unlock works; after new fingerprint app refuses biometrics with explanation; can re-enable.
Result
Status: ✅ PASS
Comments:
A6✅ PASS
Clipboard
RC5 status: PASS
Steps
- Copy password from detail view.
- Check countdown notification.
- Paste in another app.
- Wait 30s; attempt paste again.
- Try "Clear now".
Expected
- Countdown appears; paste within 30s; after 30s no paste; "Clear now" immediate.
Result
Status: ✅ PASS
Comments:
A7✅ PASS
Autofill in Your Daily Browser
Note: Chrome 131+ extra step: Chrome → Settings → Autofill services → "Autofill using another service" → restart Chrome.
RC5 status: PASS
Steps
- Enable Settings → Autofill service.
- Settings → Autofill test; confirm suggestion.
- Navigate to test login page.
- Verify suggestion.
- Fill with Password Depot.
- Log in with new credential typed manually; confirm save/update prompt.
- Negative check: look-alike domain; entry NOT offered.
Expected
- Suggestion on matching domain; save/update works; no suggestion for non-matching.
Result
Status: ✅ PASS
Comments:
A8✅ PASS
Autofill in One App
RC5 status: PASS
Steps
- Open any app with login screen (test account).
- Trigger autofill.
Expected
- Autofill works or cleanly offers nothing — no crash, no wrong entry.
Result
Status: ✅ PASS
Comments:
A9✅ PASS
Appearance, Language, Rotation, Tablet
RC5 status: PASS
Steps
- Switch appearance dark → light → system.
- Switch app language DE ↔ EN.
- Rotate device while unlocked.
- (Tablet/foldable) Verify two-pane layout.
Expected
- Switches work without restart; rotation preserves state; two-pane correct on tablets.
Result
Status: ✅ PASS
Comments:
A10✅ PASS
Stability & Error Visibility
What to test: Any crash, freeze, or silently swallowed error is a top report.
RC5 status: PASS
Steps
- If any occur, open Support data immediately.
- Copy version line and events.
- File Jira Bug Sev-0 with support data.
Expected
- No crashes, freezes, or silently swallowed errors.
Result
Status: ✅ PASS
Comments:
Part 6 — Focus Blocks C1–C11
Complete the blocks assigned to you, or any you have the setup for. All PASS in RC1, RC4, RC5; confirm no regression on RC8.
C1✅ PASS
TOTP
Setup needed: A test account with 2FA/TOTP and a reference authenticator app.
RC5 status: PASS
Steps
- Add TOTP secret via entry editor.
- Use "Scan QR code" (camera/photo).
- Compare 6-digit code with reference authenticator for ≥3 periods.
- With autofill: confirm code offered only into one-time-code field.
Expected
- Codes match for ≥3 periods; code offered only into OTP fields.
Result
Status: ✅ PASS
Comments:
C2✅ PASS
Passkeys (Android 14+)
Setup needed: Android 14+, screen lock enabled. Test site: https://webauthn.io
RC5 status: PASS
Steps
- Settings → Passkey provider → Password Depot; verify "Enabled".
- Register a new passkey on webauthn.io.
- Sign in with the passkey.
- Move passkey entry to trash.
- Attempt sign-in → expect "No matching passkey".
- Restore passkey entry.
- Attempt sign-in again → works.
Expected
- All steps behave as described.
Result
Status: ✅ PASS
Comments:
C3✅ PASS
WebDAV Sync
Setup needed: A real Nextcloud and/or Apache WebDAV server over HTTPS.
RC5 status: PASS
Steps
- Link WebDAV server.
- Initial DB upload.
- Edit entry on Android; sync; verify on Windows.
- Edit same entry on both simultaneously.
- Sync from Android.
Expected
- Initial upload succeeds; concurrent edit → conflicted copy on Android.
Result
Status: ✅ PASS
Comments:
C4✅ PASS
Windows Interop
Setup needed: Windows Password Depot 19 and same DB accessible on both.
RC5 status: PASS
Steps
- Open same .pswe alternately in Windows PD 19 and Android.
- Verify umlauts/emoji, folders, attachments, TAN lists, entry history, custom icons, second-password entry survive both directions.
- Set expiry date on Android; open in Windows; confirm date preserved.
Expected
- All content survives both directions unchanged.
Result
Status: ✅ PASS
Comments:
C5✅ PASS
Attachments
RC5 status: PASS
Steps
- Attach photo (few MB); reopen and export.
- Attach PDF (few MB); reopen and export.
- Attempt to attach file over 25 MB.
Expected
- Photo/PDF attach, export, open correctly; >25 MB refused with clear message, no crash.
Result
Status: ✅ PASS
Comments:
C6✅ PASS
Multi-Database & Master Password Change
What to test: App copy of every DB lives in app private storage; "on this device" DB has no external file.
RC5 status: PASS
Steps
- Create second DB; switch between both.
- Export copy; open via "Open database file…".
- Remove THAT entry from app — file in Downloads must still exist — and open again.
- Change master password of test DB.
- Attempt unlock with old password.
Expected
- Switching works; "Remove from app" does not delete external file; old password rejected.
Result
Status: ✅ PASS
Comments:
C7✅ PASS
Backup & Restore
RC5 status: PASS
Steps
- Databases & sync → Backup copies; create backup.
- Make changes.
- Restore earlier backup.
- Wrong password during restore; check throttle and message.
- Correct password; confirm restore.
- Attempt restore of corrupted backup.
Expected
- Correct password restores; current state saved before restore; wrong password throttle + message; corrupted backup refused, active DB untouched.
Result
Status: ✅ PASS
Comments:
C8✅ PASS
Enterprise Thin Client
Setup needed: Office test server (Enterprise Server 20).
RC5 status: PASS
Steps
- App → "Enterprise server…".
- Enter address/port; log in.
- First connect: verify TLS fingerprint dialog.
- Browse and search entries.
- Edit entry and save.
Expected
- TLS fingerprint dialog first connect; login succeeds; browse/search/edit work.
Result
Status: ✅ PASS
Comments:
C9✅ PASS
Enterprise Offline Copy
Setup needed: Enterprise Server 20, TCP port 25020, DB with offline right granted.
RC5 status: PASS
Steps
- Sign in; tap "Save offline copy…".
- Enter server password.
- Tap "Load databases" — confirm TLS fingerprint once.
- Pick DB; confirm copy saved.
- Sign out; tap "Open offline copy".
- Create/edit entry offline; note waiting-changes counter.
- Settings → Sync… → "Send changes to the server".
Expected
- All steps behave as described.
Result
Status: ✅ PASS
Comments:
C10✅ PASS
Enterprise Single Sign-On (OpenID Connect / Entra ID)
Setup needed: Enterprise Server 20 with configured OIDC or Entra ID provider.
RC5 status: PASS
Steps
- Choose "Single sign-on (OpenID Connect / Entra ID)"; tap "Connect".
- Complete sign-in in browser.
- Sign out; use "Sign in with a different account".
- Start sign-in and cancel in browser.
- Sign in with account server does not know.
Expected
- All scenarios behave as described.
Result
Status: ✅ PASS
Comments:
C11✅ PASS
Hand-Over of Previous-App Offline Changes
Setup needed: Enterprise Server 20, TCP port 25020.
RC5 status: PASS
Steps
- Start with previous Password Depot for Android installed and Enterprise DB with unsent offline changes.
- Update to RC8; open "Import from previous app".
- Verify report names number of unsent changes.
- Tap "Send to the server…".
- Confirm note disappears and changes on server.
Expected
- All steps behave as described.
Result
Status: ✅ PASS
Comments:
5 · Device Matrix Contribution
| Dimension | Variant | Covered | Notes |
|---|
| Keyboard | Gboard | ✅ | |
| Keyboard | Samsung Keyboard | ✅ | |
| Keyboard | SwiftKey | ✅ | |
| Browser | Chrome | ✅ | |
| Browser | Edge | ✅ | |
| Browser | Firefox | ✅ | |
| Browser | Samsung Internet | ❌ | |
| Autofill style | Android 11+ inline chips | ✅ | |
| Autofill style | Android ≤13 dropdown | ✅ | |
| Clipboard | Samsung clipboard behavior | ✅ | |
| Clipboard | Pixel clipboard behavior | n/a | |
| Clipboard | Xiaomi clipboard behavior | ✅ | |
| Biometrics | Fingerprint | ✅ | |
| Biometrics | Face unlock | ✅ | |
| Biometrics | Both enrolled | ✅ | |
| OEM quirks | Xiaomi/HyperOS battery saver — auto-lock reliable? | n/a | |
| OEM quirks | Samsung battery saver — session killed mid-edit? | ✅ | |
| Form factor | Phone | ✅ | |
| Form factor | Tablet (≥ 600 dp) | ✅ | |
| Form factor | Foldable | n/a | |
| Storage | FTPS / FTPES | ✅ | |
| Storage | HiDrive | ✅ | |
| Migration | 19.x migration with key-file database | ✅ | |
| RC8 Smoke | Google Play internal test track install | ✅ | |
6 · Reporting Reference
| Jira Project | Android Client (AC) |
|---|
| Affects Version | 20.0.0 |
|---|
| Build line | 20.0.0 RC8 (2008) |
|---|
| Release | RC8 · Google Play submission pending |
|---|
| Severity 0 | crash · data loss · lock-out |
|---|
| Severity 1 | feature wrong or unusable |
|---|
| Severity 2 | wrong, has a workaround |
|---|
| Severity 3 | visual / text |
|---|
Support data: lock the app → tap "Support data…" on the unlock screen.