Password Depot for Android — RC9 QA Test Report
Build 20.0.0 RC9 (2009) · Release Candidate 9 · Regression of 20.0.0 RC8 · RC8 QA Report · 2026-10-01 · Generated 10/5/2026, 5:41:00 PM
1 · Environment
| Device / Android | Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15 |
|---|
| Keyboard | Gboard |
|---|
| Browser(s) | Chrome 154 |
|---|
| Build line | 20.0.0 RC9 (2009) |
|---|
| Tester | Sheva Ma |
|---|
| Date started | 2026-10-05 |
|---|
2 · Summary
| Block | Total | ✅ Pass/Fixed | ❌ Fail | 🚫 Blocked | ⏭️ Skip | 🔄 In Progress | ⬜ Pending |
|---|
| Part 0 — RC8 FAILURES Re-Test | 4 | 3 | 1 | 0 | 0 | 0 | 0 |
| Part 1 — RC8 NEW BUGS Re-Test | 2 | 1 | 0 | 0 | 1 | 0 | 0 |
| Part 2 — RC5 NEW BUGS Regression (10) | 10 | 10 | 0 | 0 | 0 | 0 | 0 |
| Part 3 — RC9 Smoke: Google Play Readiness | 7 | 7 | 0 | 0 | 0 | 0 | 0 |
| Part 4 — Security & MDM | 4 | 2 | 0 | 2 | 0 | 0 | 0 |
| Part 5 — RC1 Reported Bugs Regression (10 PASS) | 10 | 10 | 0 | 0 | 0 | 0 | 0 |
| Part 6 — Beta21 / RC1 Regression (R18-1 – R18-7) | 7 | 7 | 0 | 0 | 0 | 0 | 0 |
| Part 7 — Core Pass: A1–A10 (Every Tester, Every Device) | 10 | 10 | 0 | 0 | 0 | 0 | 0 |
| Part 8 — Focus Blocks C1–C11 | 11 | 11 | 0 | 0 | 0 | 0 | 0 |
| Total | 65 | 61 | 1 | 2 | 1 | 0 | 0 |
| Items tested / total | 63 / 65 |
|---|
| Pass rate (of decided items) | 98% |
|---|
| Failures | 1 |
|---|
| Blocked items | 2 |
|---|
| New bugs discovered (manual entry) | 13 |
|---|
| Closed bugs (verified fixed this round) | 0 |
|---|
3a · RC8 FAILURES Re-Test (1)
RC8-F2AC-736[UX/Storage] Support listing databases automatically for WebDAV, FTP, and HiDrive storage instead of requiring full file paths
Section: Part 0 — RC8 FAILURES Re-Test
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
RC8 note: RC8: "I still not able to proceed if I input the URL without .pswe on RC8."
Comments: Verified on RC9 build 2009, FTP works fine now, but the HiDrive has issue to login:
HiDrive: if I just input the url:
HiDrive Login - Der Online-Speicher für Dateien, Bilder & Musik! , it won’t redirect to https://webdav.hidrive.strato.com, which caused open drive failed to load the folders.
3b · RC8 NEW BUGS Re-Test
RC8-N2AC-767[Server DB] Support adding and editing additional URLs for entries — ✅ FIXED
Verified on device: — not provided —
Comments: — none —
3c · RC5 NEW BUGS Regression (10)
RC5-N2AC-717✅ PASS
Switching to standard user offline DB still prompts for SSO login after saving SSO offline DB
RC8 note: RC8: Verified PASS.
Tested device: — not provided —
Comments: — none —
RC5-N3AC-732✅ PASS
Server certificate confirmation prompt reappears when clicking "Load databases" in "Save offline copy" after already trusting the certificate
RC8 note: RC8: Verified PASS.
Tested device: — not provided —
Comments: — none —
RC5-N4AC-679✅ PASS
Home screen: Keep "Another way in" section expanded by default when databases exist
RC8 note: RC8: Verified PASS.
Tested device: — not provided —
Comments: — none —
RC5-N5AC-733✅ PASS
[UX] Expand markdown toolbar items in full-screen comment editor instead of keeping them in the overflow dropdown
RC8 note: RC8: Verified PASS.
Tested device: — not provided —
Comments: — none —
RC5-N6AC-734✅ PASS
Align "Conditional access" tab in Entry editor with Windows client (UI items, warning levels & access triggers)
RC8 note: RC8: Verified PASS.
Tested device: — not provided —
Comments: — none —
RC5-N9AC-738✅ PASS
[Support Data] Copy button fails to copy logs under "From the autofill process"
RC8 note: RC8: Verified PASS.
Tested device: — not provided —
Comments: — none —
RC5-N10AC-739✅ PASS
[Support Data] Include app version, Android OS version, and default browser version in support data logs
RC8 note: RC8: Verified PASS.
Tested device: — not provided —
Comments: — none —
RC5-N11AC-698✅ PASS
[Tablet][Enterprise] Server DB does not use two-pane (master-detail) layout unlike Local DB
RC8 note: RC8: Verified PASS.
Tested device: — not provided —
Comments: — none —
RC5-N12AC-704✅ PASS
[Autofill][Android 14 Tablet] "Setup Autofill" banner remains visible after enabling autofill service and credential provider
RC8 note: RC8: Verified PASS.
Tested device: — not provided —
Comments: — none —
RC5-N13AC-707✅ PASS
[Security/Settings] Enable lowercase, uppercase, and numbers by default in Master Password Policy
RC8 note: RC8: Verified PASS.
Tested device: — not provided —
Comments: — none —
3d · Failures on the checklist (1)
RC8-F2AC-736[UX/Storage] Support listing databases automatically for WebDAV, FTP, and HiDrive storage instead of requiring full file paths
Section: Part 0 — RC8 FAILURES Re-Test
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
RC8 status: FAIL — RC8: "I still not able to proceed if I input the URL without .pswe on RC8."
Comments: Verified on RC9 build 2009, FTP works fine now, but the HiDrive has issue to login:
HiDrive: if I just input the url:
HiDrive Login - Der Online-Speicher für Dateien, Bilder & Musik! , it won’t redirect to https://webdav.hidrive.strato.com, which caused open drive failed to load the folders.
3e · New Bugs Discovered (Manual Entry — this round) (13)
NEW #1AC-773Sev-2UI/UX: Support database switching on tablet portrait and phone — unify database selector in the top bar
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
Currently, switching between databases is only convenient on tablet landscape mode, where the left pane allows switching between local DBs and server DBs. On tablet portrait and phone, there is no unified way to switch databases — the user must navigate back and re-enter the target database, which is cumbersome.
We propose unifying the database selector across all form factors (phone, tablet portrait, tablet landscape) by making the database name area in the top-left of the top bar a clickable dropdown, consistent with the existing localdb1002 ▼ design.
Proposal
Keep the existing localdb1002 ▼ design
The database name in the top bar should remain clickable, as it already is for local DBs.
Clicking ▼ opens a unified database list
The dropdown should show:
All local databases
All connected server databases (if signed in)
All configured cloud databases
A "Back to server list" option (only when the current DB is a server DB)
An "Add database…" entry
Selecting a database switches directly to it
No need to navigate back to the database manager.
Visual Mockup
Top bar (example: Server DB open):
┌─────────────────────────────────────────────┐
│ Private_DB_suser01.pswe ▼ 🔄 ⚙️ Sign out │
│ 172.20.10.5:8714 · suser01 │
└─────────────────────────────────────────────┘
Clicking ▼ opens:
┌─────────────────────────────────────────────┐
│ 🔍 Search databases… │
├─────────────────────────────────────────────┤
│ 🖥️ Server databases │
│ ✓ Private_DB_suser01.pswe │
│ Private_DB_suser02.pswe │
│ Shared_Team.pswe │
├─────────────────────────────────────────────┤
│ ☁️ Cloud databases │
│ MyVault.pswe OneDrive │
│ WorkVault.pswe Google Drive │
│ Backup.pswe Dropbox │
├─────────────────────────────────────────────┤
│ 💾 Local databases │
│ localdb1002 │
│ localdb1003 │
├─────────────────────────────────────────────┤
│ ⬅ Back to server list │
│ + Add database… │
└─────────────────────────────────────────────┘
Form-factor-specific behavior
Form factor | Behavior when clicking ▼ |
|---|
Phone (portrait / landscape) | Show the full unified list (Server + Cloud + Local) |
Tablet portrait | Show the full unified list (Server + Cloud + Local) |
Tablet landscape | Left pane already handles switching. When a server DB is open, clicking ▼ should only show the signed-in server DB list. When a local DB is open, clicking ▼ should only show the local DB list. This avoids duplicating the left-pane navigation. |
Rationale
Consistency: Local DBs already use a ▼ dropdown; extending this to server and cloud DBs makes the interaction uniform.
Efficiency: Users on phones and tablet portrait currently have to navigate back to the database manager to switch DBs. A dropdown removes that friction.
Clarity: Grouping by type (Server / Cloud / Local) with icons and subtitles (e.g., "OneDrive", "172.20.10.5:8714") makes it immediately clear what each entry is.
Scalability: Future database types (FTP, WebDAV, etc.) can be added as new groups without redesigning the UI.
Acceptance Criteria
The database name in the top bar is clickable on phone, tablet portrait, and tablet landscape.
Clicking ▼ opens a dropdown list of databases grouped by type (Server / Cloud / Local).
Selecting a database switches to it directly (prompting for password if locked).
On tablet landscape, the dropdown only shows the relevant subset (server DB list when a server DB is open; local DB list when a local DB is open).
An "Add database…" entry is available at the bottom of the dropdown.
The current database is marked with a checkmark (✓).
The dropdown is scrollable and searchable when the list is long.
NEW #2AC-774Sev-2Autofill prompt "Save username and password to Password Depot?" appears after SSO login, but the entry is never saved — and it should not appear if saving is not possible
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
When a user signs in to an Enterprise Server database via SSO (Entra ID / OpenID Connect) for the first time, the Azure login page is shown in the browser. Immediately after the SSO authentication completes, the Android client displays the autofill prompt:
"Save username and password to Password Depot?"
[No thanks] [Save]
However, after tapping Save, no entry is created in any of the following places:
The Enterprise Server database that was just opened
Any other open server database
Any recent local database
The user has no way to find the saved entry, and no feedback is given about where it was (or was not) stored.
Steps to Reproduce
On the Android client, sign in to an Enterprise Server 20 database using SSO (Entra ID / OpenID Connect) for the first time.
The Azure login page opens in the browser; complete the sign-in.
After the SSO authentication completes, the prompt "Save username and password to Password Depot?" appears.
Tap Save.
Open the server database that was just connected.
Check for a new entry containing the SSO credentials.
Also check any recently opened local databases.
Actual Result
The prompt appears after SSO login.
After tapping Save, no entry is created in the server database or any local database.
The user cannot locate the saved credentials anywhere.
No error message or explanation is shown.
Expected Result
Either of the following behaviours is acceptable:
Option A — Do not show the prompt if saving is not possible
If SSO credentials cannot be saved to Password Depot (e.g., because SSO uses a token-based flow and no reusable username/password pair exists), the prompt should not appear at all. Showing it creates a false expectation.
Option B — Actually save the entry (preferred)
If the prompt is shown and the user taps Save, the entry should be actually created. The preferred target is the most recently opened local database, since SSO credentials may not be appropriate to store inside the Enterprise Server database itself. The user should receive confirmation (e.g., "Saved to localdb1002") so they know where the entry went.
Additional Notes
This issue occurs specifically with SSO login, where the authentication is handled by an external identity provider (Azure / Entra ID) rather than a direct username/password pair entered into Password Depot.
The prompt appears because the browser detects a login form submission during the SSO flow, but the credentials are not reusable in the same way as a standard form login.
The prompt is misleading and should either be suppressed for SSO flows or handled with a clear save target and confirmation.
Suggested Fix
Detect SSO login context and suppress the autofill save prompt if no reusable credentials can be captured.
If the prompt is kept, ensure the entry is actually written to a defined location (e.g., the most recent local DB) and show a confirmation message with the database name.
Add logging to record why the save was skipped or where it was stored, to aid future debugging.
NEW #3AC-775Sev-2Refresh button disappears from the top bar when opening an entry detail view Tested device: Phone: Galaxy S22, Android 15, Tablet: Pixel Tablet, Android 15
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
When a user opens a database and is viewing the entry list, the top bar shows the Refresh button (🔄) alongside the settings and sign-out actions. This allows the user to manually refresh the server database and pull the latest changes.
However, as soon as the user taps an entry to open its detail view, the Refresh button disappears from the top bar. The settings (⚙️) and sign-out actions remain visible, but the refresh action is gone.
This is inconsistent — refreshing the database should be available regardless of whether the user is viewing the entry list or an entry detail. In fact, refreshing while viewing an entry is arguably more important, because the user may want to check whether the entry has been updated on the server (e.g., by another device or another user).
Steps to Reproduce
Sign in to an Enterprise Server database on the Android client.
In the entry list view, confirm that the Refresh button is visible in the top bar.
Tap any entry to open its detail view.
Observe the top bar.
Actual Result
The Refresh button disappears from the top bar in the entry detail view.
Only the settings (⚙️) and sign-out actions remain.
The user cannot refresh the database without first navigating back to the entry list.
Expected Result
The Refresh button should remain visible in the top bar in both the entry list view and the entry detail view.
The user should be able to refresh the database at any time, regardless of which screen they are on.
NEW #4AC-777Sev-2UI/UX: Move Edit and overflow (⋮) buttons to the right side of the entry detail header in tablet portrait mode
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
In the entry detail view on tablet portrait, the Edit button and the overflow menu (⋮) are positioned on the left side of the detail header, directly below the entry title. This placement is inconsistent with the tablet landscape layout, where the same actions are correctly aligned to the right side of the header.
Since the landscape layout is already correct, this improvement only targets tablet portrait (and, if applicable, phone portrait) to bring it in line with the landscape behaviour.
Current Layout (Tablet Portrait)
┌─────────────────────────────────────────────┐
│ 🔒 account.teamviewer.com │
│ Password │
│ │
│ ┌────────┐ ┌───┐ │
│ │ ✏️ Edit │ │ ⋮ │ │
│ └────────┘ └───┘ │
│ │
│ Credentials │
│ ... │
└─────────────────────────────────────────────┘
The Edit and ⋮ buttons sit on the left, immediately under the title, which:
Differs from the already-correct landscape layout
Pushes content downward unnecessarily
Breaks the standard "actions on the right" pattern used elsewhere in the app
Proposed Layout (Tablet Portrait)
┌─────────────────────────────────────────────┐
│ 🔒 account.teamviewer.com │
│ Password │
│ │
│ ┌────────┐ ┌───┐ │
│ │ ✏️ Edit │ │ ⋮ │ │
│ └────────┘ └───┘ │
│ │
│ Credentials │
│ ... │
└─────────────────────────────────────────────┘
The Edit and ⋮ buttons move to the right side, on the same line as the entry title.
Scope
Form factor | Current behaviour | Action |
|---|
Tablet landscape | Actions already on the right ✅ | No change |
Tablet portrait | Actions on the left ❌ | Fix — move to the right |
Phone portrait | If also on the left ❌ | Apply the same fix for consistency |
Only tablet portrait is in scope for this ticket. Landscape is already correct and should not be modified.
Acceptance Criteria
In tablet portrait, the Edit and ⋮ buttons appear on the right side.
The title and metadata remain left-aligned.
Layout remains stable when the entry title is long (no overlap, no wrapping issues).
Tablet landscape layout remains unchanged.
NEW #5AC-779Sev-2UX: Allow selecting a target folder when saving an entry from the browser autofill prompt
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
When a user logs in to a website in the browser and Password Depot offers to save the credentials, the save flow does not allow the user to choose which folder the new entry should be saved into.
Currently, the entry is saved to the database root (or to an unspecified default location), which means:
Users with many folders (e.g., "Work", "Personal", "Finance", "Clients") cannot file the new entry where it belongs
The user has to open the app afterwards, find the entry, and manually move it to the correct folder
On larger databases this creates clutter and makes entries harder to find later
The same applies to the "Replace saved password?" dialog — there is no way to change the target folder at that point either.
Current Flow
Step 1 — Save to Password Depot
Step 2 — Replace saved password?
Neither dialog lets the user pick a folder.
Proposed Improvement
Add a folder selector to both dialogs, so the user can choose where the entry is saved.
Step 1 — Save to Password Depot (with folder selector)
┌─────────────────────────────────────┐
│ 🔒 │
│ Save to Password Depot │
│ ● Database: localdb1002 │
│ ● for account.teamviewer.com │
│ │
│ Save to folder │
│ [ 📁 / (root) ▼ ] │
│ │
│ User name │
│ ─ │
│ │
│ Password │
│ •••••••• │
│ │
│ Master password │
│ [___________________] │
│ │
│ [ Unlock and save ] │
│ Don't save │
└─────────────────────────────────────┘
Step 2 — Replace saved password? (with folder option)
┌─────────────────────────────────────┐
│ 🔒 │
│ Replace saved password? │
│ The entry account.teamviewer.com │
│ (—) already exists for this │
│ target. Replace its saved │
│ password with the new one? │
│ │
│ Save to folder │
│ [ 📁 Work / Clients ▼ ] │
│ │
│ User name │
│ ─ │
│ │
│ Password │
│ •••••••• │
│ │
│ [ Replace password ] │
│ [ Save as new entry ] │
│ Cancel │
└─────────────────────────────────────┘
Folder picker behaviour:
Defaults to the last used folder
Shows the same folder tree as the main app
Allows creating a new folder inline (optional, nice-to-have)
Remembers the last selected folder for the next autofill save
Acceptance Criteria
The "Save to Password Depot" dialog includes a folder selector.
The "Replace saved password?" dialog includes a folder selector (used when saving as a new entry).
The folder selector shows the same folder hierarchy as the main app.
The selected folder is respected when the entry is created.
The default folder is the database root or the last used folder.
If the user does not interact with the folder selector, the entry is saved to the default location as before.
NEW #6AC-780Sev-2UI/UX: Master password policy dialog should apply changes immediately — remove the Save and Cancel buttons for consistency with all other settings
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
In the Android client's Settings screen, every other setting applies immediately when the user toggles it or changes its value. There is no Save or Cancel button anywhere else in Settings — the change takes effect right away and the screen simply reflects the new state.
The Master password policy dialog is the only exception. It shows a dedicated Save and Cancel button at the bottom, which:
Breaks the interaction pattern used everywhere else in Settings
Makes the user wonder whether other settings also require a save
Adds unnecessary friction (an extra tap to confirm)
Creates a risk of losing changes if the user navigates away without tapping Save
For a consistent experience, this dialog should behave like the rest of Settings: changes apply immediately, with no Save or Cancel buttons.
Current Behaviour
Every other Settings row applies immediately — only this dialog has Save / Cancel.
Proposed Behaviour
┌─────────────────────────────────────┐
│ Master password policy │
│ Applies to new master passwords │
│ (creating a database, changing │
│ the master password). Managed │
│ settings can only tighten it. │
│ │
│ Minimum length │
│ [ 8 ] │
│ │
│ Lowercase letters required [●] │
│ Uppercase letters required [○] │
│ Numbers required [●] │
│ Special characters required [○] │
└─────────────────────────────────────┘
Changes apply immediately, exactly like all other Settings entries.
The dialog can still be closed with the standard back gesture or a close (✕) action.
A subtle inline confirmation (e.g., "Policy updated") could optionally be shown, matching the pattern used elsewhere.
Acceptance Criteria
The Master password policy dialog no longer shows Save and Cancel buttons.
Changing any value in the dialog (minimum length, letter/number/special-character toggles) takes effect immediately.
Closing the dialog without any change leaves the policy untouched.
The behaviour matches all other Settings entries (immediate apply, no confirm step).
If a change cannot be applied (e.g., managed settings only tighten the policy), a clear inline message explains why, instead of blocking on a Save button.
NEW #7AC-782Sev-2UI/UX: Replace chevron with an action icon on "Create backup copy now" and show a success/failure toast after the action
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
In Settings → Backup copies, the row "Create backup copy now" currently shows a chevron (>) on the right side, identical to navigation rows such as Number of stored copies, External folder, and Backup copies.
However, this row is not a navigation entry — tapping it immediately performs an action (creating a backup copy). Using the chevron is misleading, because elsewhere in Settings the chevron consistently means "opens a sub-page".
Additionally, after tapping the row, there is no feedback telling the user whether the backup was created successfully or whether it failed. The only indirect signal is the Last copy: timestamp, which the user may not notice.
Current Behaviour
Problems:
The > icon implies navigation, but the row performs an action.
No success or failure feedback is shown after tapping.
Proposed Behaviour
Replace the chevron with an action icon
Use a "run / execute now" icon instead of >, for example a refresh-style circular arrow (⟳):
┌─────────────────────────────────────────────┐
│ Create backup copy now ↻ │
│ Last copy: 10/02/2026 4:39 PM │
├─────────────────────────────────────────────┤
│ When saving the database [ ● ] │
│ When opening the database [ ○ ] │
│ Number of stored copies 7 > │
│ External folder > │
│ Backup copies > │
└─────────────────────────────────────────────┘
The other rows keep their > chevron, since they genuinely open sub-pages. This visually distinguishes "action" rows from "navigation" rows.
Show a result toast after the action
After tapping the row, display a short snackbar / toast:
On success:
✅ Backup copy created
(optionally include the timestamp or file name)
On failure:
⚠️ Could not create backup copy
(optionally include a short reason, e.g. "Not enough storage")
While in progress (optional):
Briefly disable the row and show a spinner or "Creating backup…" state to prevent double-taps.
Acceptance Criteria
The > chevron on "Create backup copy now" is replaced with an action icon (e.g., ↻).
Other rows in the same group keep their > chevron.
Tapping the row triggers the backup immediately.
A success toast is shown when the backup is created.
A failure toast is shown when the backup cannot be created.
The Last copy: timestamp updates after a successful backup.
The row is briefly disabled or shows a progress state while the backup runs, to prevent duplicate taps.
NEW #8AC-783Sev-2UI/UX: Replace the "Number of stored copies" dialog with an inline stepper control (− / input / +) in Settings
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
In Settings → Backup copies, the row "Number of stored copies" currently shows the current value followed by a chevron (7 >). Tapping the row opens a separate dialog where the user can edit the number.
Since this setting only changes a single numeric value, opening a full dialog is unnecessarily heavy. An inline stepper control directly on the Settings row would be faster and more consistent with how numeric settings are handled in modern mobile apps.
Current Behaviour
┌─────────────────────────────────────────────────────┐
│ Number of stored copies 7 > │
└─────────────────────────────────────────────────────┘
↓ tap
┌─────────────────────────────────────┐
│ Number of stored copies │
│ │
│ [ 7 ] │
│ │
│ [ Save ] [ Cancel ] │
└─────────────────────────────────────┘
Problems:
Two taps required just to change one number (open dialog → confirm).
Inconsistent with the rest of Settings, where most values are changed inline.
A dialog for a single numeric field feels heavier than necessary.
Proposed Behaviour
Replace the value + chevron with an inline stepper on the row itself:
text
┌─────────────────────────────────────────────────────┐
│ Number of stored copies ─ [ 7 ] + │
│ Copies older than this are removed. │
└─────────────────────────────────────────────────────┘
Control behaviour:
Element | Behaviour |
|---|
− button | Decreases the value by 1. Disabled when the minimum is reached (e.g., 1). |
Input field | Shows the current value. Tapping it opens the numeric keyboard for direct entry. |
+ button | Increases the value by 1. Disabled when the maximum is reached (e.g., 99). |
Validation | Non-numeric input is ignored; values outside the range are clamped automatically. |
Apply | Changes apply immediately — no Save or Cancel buttons, consistent with the rest of Settings. |
Subtitle (optional): Add a short line under the row explaining the effect, e.g., "Copies older than this are removed." This replaces the need for a separate dialog with explanatory text.
Comparison
| Current | Proposed |
|---|
Taps to change value | Open row → edit → Save (3 taps) | Tap + / − once (1 tap) |
Visual consistency | Dialog (unique in this section) | Inline, matches other Settings |
Screen space | Full-screen modal | None |
Direct input | Yes (via dialog) | Yes (tap the field) |
Acceptance Criteria
The "Number of stored copies" row no longer opens a dialog.
The row shows a stepper control: − [ value ] +.
− and + adjust the value by 1 and are disabled at min/max.
Tapping the input field opens the numeric keyboard for direct entry.
Non-numeric input is ignored; out-of-range values are clamped.
Changes apply immediately (no Save / Cancel buttons).
The row remains visually consistent with other Settings entries.
NEW #9AC-791Sev-2UX: Autofill only searches the server DB when both a local DB and a server DB are unlocked — should search both, or prioritise the most recently opened DB
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
When both a local database and a server database are open and unlocked in the Android client at the same time, the autofill feature only searches for matching entries in the server database.
This happens regardless of which database the user opened most recently. Even if the user just opened a local database and is actively working in it, autofill still ignores it and only looks at the server DB.
As a result, entries saved in the local database are never offered for autofill, even though the local DB is unlocked and available.
Steps to Reproduce
On the Android client, sign in to an Enterprise Server database (leave it unlocked).
Also open a local database (leave it unlocked).
Switch to the local database and open an entry in it.
Open a browser and trigger autofill on a login page that matches an entry in the local database.
Observe which entries are offered.
Actual Result
Autofill only searches the server database.
Entries from the local database are not offered, even though the local DB is unlocked and was the most recently used database.
The user cannot autofill entries from the local DB unless they close or lock the server DB first.
Expected Result
When both a local DB and a server DB are unlocked, autofill should search both databases and offer matching entries from either. If multiple matches exist, they should be presented in a clear list (e.g., grouped by database).
Alternatively, at minimum, autofill should prioritise the most recently opened / most recently used database, so that if the local DB is active, its entries are offered first or included.
Suggested Behaviour
Option A — Search both databases (preferred)
Autofill aggregates results from all unlocked databases and shows them in one list, grouped or labelled by source:
text
┌─────────────────────────────────────────────┐
│ Autofill suggestions │
├─────────────────────────────────────────────┤
│ 💾 localdb1002 │
│ account.teamviewer.com │
├─────────────────────────────────────────────┤
│ 🖥️ Private_DB_suser01.pswe │
│ account.teamviewer.com │
└─────────────────────────────────────────────┘
Option B — Prioritise the most recently opened database
If the local DB is the active one, autofill searches it first and only falls back to the server DB if no match is found.
Acceptance Criteria
When both a local DB and a server DB are unlocked, autofill searches both.
Entries from the local DB are offered when they match, even if a server DB is also unlocked.
The source database of each suggestion is visible to the user (e.g., labelled or grouped).
If both databases contain a matching entry, the user can choose which one to use.
Behaviour is consistent regardless of which database was opened first.
NEW #10AC-814Sev-2Add search functionality across all database list views (Local, Cloud, Server)
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
Currently, the app does not support a search/filter function in database list screens. When users have many databases, locating a specific database is difficult and time-consuming.
NEW #11AC-815Sev-2UI/UX: Use standard accordion chevron directions for "Another way in" section
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
Current Behavior:
In the "Another way in" section on the home screen:
When collapsed, the indicator arrow points right (>).
When expanded, the indicator arrow points down (v).
Problems / UX Rationale:
In mobile UX (Material Design / iOS), a right chevron (>) strongly indicates page navigation / drill-down to a new screen. Because the sub-options inside "Another way in" (e.g., "Open database file", "Open from cloud") already use right chevrons (>) to navigate, having a right chevron on the collapsible header creates confusion and inconsistency.
When the section is already expanded, a downward arrow does not intuitively convey "collapse/hide upward".
Proposed Solution:
Adopt the standard mobile collapsible / accordion pattern:
Acceptance Criteria:
When "Another way in" is collapsed, the arrow icon points down (⌄).
When "Another way in" is expanded, the arrow icon points up (⌃).
Tapping the section toggles between expanded and collapsed states with the matching chevron direction.
NEW #12AC-816Sev-2Local database: Local database permanently converts to cloud database after syncing, causing blocking timeouts on offline operations
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
Impact
Syncing a local database to cloud storage permanently converts it into a cloud database. This causes offline work to block and hang. Users cannot open or change entries smoothly when the network is unavailable.
Expected behaviour
Syncing a local database to cloud storage should not turn it into a cloud-only database.
Read and write actions should work directly on the local copy.
Cloud sync should only run during automatic sync intervals or when the user triggers it manually.
If offline, the app should use the local copy immediately without waiting for a network timeout.
Actual behaviour
After syncing a local database to cloud storage, the database becomes a cloud database.
When the network is unavailable or the cloud storage is unreachable:
Opening the database hangs and blocks the UI until the cloud connection times out.
CRUD operations such as adding, editing, moving, and deleting entries also hang until the connection times out.
The database icon/type changes directly into a cloud database after syncing.
Steps to reproduce
Create a new local database.
Sync the database to WebDAV or another cloud storage service.
Notice that the database changes directly into a cloud database.
Disconnect the network or switch the device to Airplane Mode.
Attempt to open the database.
Attempt a CRUD operation such as:
Environment
Local database synced to WebDAV or another cloud storage service
Offline conditions
Network unavailable or device in Airplane Mode
Client version: v20.0.0 RC9 build 2009
NEW #13AC-817Sev-2Settings: Separate App-level and Database-level Settings in UI and Tablet Navigation
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Description:
Summary
Currently, the Settings menu mixes database-level settings and app-level settings together into a single flat list. This causes confusion for users because it is unclear which settings apply globally across the entire app and which settings are specific to the currently opened database. Furthermore, in tablet mode, navigation does not clearly differentiate between global and database-specific settings.
Problem Analysis & Current State
Proposed Classification of Settings
Database-Level Settings (Scoped to individual DB):
Security: Each database should have its own security configurations (e.g., encryption settings, password policies, auto-lock behavior per DB).
Backup copies: Backup frequency, retention, and storage path specific to that database.
Entry Point: Accessible when a database is open (e.g., via a Settings button/icon in the database view top bar / action bar).
App-Level Settings (Global across all DBs):
Autofill & passkeys: System-wide autofill provider and passkey behavior.
Databases & sync: Global sync schedules, cloud accounts, default storage locations.
General: App language, theme, startup behavior, etc.
Support: Help center, contact support, diagnostic logs, app version.
Entry Point: Main navigation / left sidebar settings button.
Tablet Mode Navigation Improvement
Left Sidebar Settings Button: Clicking Settings on the left navigation bar should exclusively display App-level Settings.
Database View Toolbar: When any database is opened (in the right panel / detail view), add a dedicated Database Settings button in the top action bar to open Database-level Settings for that specific database.
Acceptance Criteria
Settings options are clearly separated into App-level settings and Database-level settings.
In Tablet mode:
Left bar "Settings" button opens only App-level settings (Autofill & passkeys, Databases & sync, General, Support).
An open database view provides an entry point (e.g., settings icon in the top right / header) to access that database's specific settings (Security, Backup copies).
The UI clearly communicates the scope of each setting so users are not confused about whether a setting is global or per-database.
3f · Closed Bugs (Verified Fixed — this round) (0)
No closed bugs were logged this round.
3g · Blocked Items (2)
SEC-2MDM bans (export, cloud, autofill, clipboard) enforced at the sink
Section: Part 4 — Security & MDM
Blocker info: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Comments: MDM is disabled.
SEC-3MDM bans enforced in the autofill / passkey process (from round 5)
Section: Part 4 — Security & MDM
Blocker info: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Comments: MDM is disabled.
3h · Skipped (1)
| ID | Title | Reason |
|---|
| RC8-N1 | Unable to access Server DB Settings on Tablet (Left rail Settings opens Local/Cloud DB settings instead) | This is not ready for test. |
4 · Detailed Results
Part 0 — RC8 FAILURES Re-Test
These are the 4 failures from the RC8 QA Report (2026-10-01, section 3b): 3 reopened RC5 New Bugs plus AC-624 which was reopened on Pixel Tablet. This is the highest-priority block.
RC8-F1AC-714Sev-2✅ PASS
Server offline DB shows "No entry matches" and empty list in Autofill test after Server DB login and PIN unlock
Setup needed: Enterprise Server DB with offline copy; Autofill test page.
RC8 status: FAIL — RC8: "Autofill test is not working correctly for offline DB now."
Steps
- Sign in to the Server DB and save an offline copy.
- Open the offline DB; unlock with PIN.
- Go to Settings → Autofill test.
- Check whether entries are listed / matched.
- Trigger autofill on a test login page.
Expected
- Entries are listed and matched in the Autofill test page.
- Autofill offers the matching entry — no "No entry matches" / empty list.
Result
Status: ✅ PASS
Comments:
RC8-F2AC-736Sev-2❌ FAIL
[UX/Storage] Support listing databases automatically for WebDAV, FTP, and HiDrive storage instead of requiring full file paths
Setup needed: A WebDAV / FTP / HiDrive account with multiple .pswe databases.
RC8 status: FAIL — RC8: "I still not able to proceed if I input the URL without .pswe on RC8."
Steps
- Open "Open from cloud…" / "Storage location & sync".
- Add a WebDAV / FTP / HiDrive storage location.
- Enter server address and credentials.
- Check whether the client automatically lists available .pswe databases.
- Pick one from the list.
Expected
- Available .pswe databases are listed automatically.
- User can select from the list — no full path typing required.
Result
Status: ❌ FAIL
Tested device: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Comments:
RC8-F3AC-737Sev-2✅ PASS
[UI/UX] Differentiate icons for Sidebar navigation items (Home, Entries, DB) and database storage types (Local, Cloud, Offline)
Setup needed: A device with at least one Local, one Cloud-synced, and one Offline DB.
RC8 status: FAIL — RC8: "I see RC8 20.0.0 (2008) is ready on Google Play, but I still not see this feature on it, hence reopen the it."
Steps
- Open the navigation drawer / sidebar.
- Compare icons for Home, Entries, and the "Your Databases" list.
- Compare icons for Local, Cloud, and Offline DBs.
Expected
- Home / Entries / DB use distinct icons.
- Local / Cloud / Offline DBs are visually distinguishable.
Result
Status: ✅ PASS
Comments:
RC8-F4AC-624Sev-2✅ PASS
Autofill: Autofill in Edge browser fails to detect target URL (unknown target)
Setup needed: Google Pixel Tablet (Android 15, API 35); Edge 153.0.4234.49 (com.microsoft.emmx).
RC8 status: FAIL — RC8: "Reproduced this issue again on Google Pixel tablet, on Edge browser."
Steps
- Open Microsoft Edge on the Pixel Tablet.
- Navigate to a login page with a matching saved entry.
- Trigger autofill.
- Check whether Edge is recognised as a browser and the target URL is detected.
- Verify the matching entry is suggested.
Expected
- Edge is recognised as a browser.
- The target URL is detected.
- The matching entry is suggested.
Result
Status: ✅ PASS
Comments:
Part 1 — RC8 NEW BUGS Re-Test
These are the 2 New Bugs discovered in the RC8 QA Report (2026-10-01, section 3c). Each must be re-tested on RC9.
RC8-N1AC-766Sev-2⏭️ SKIP
Unable to access Server DB Settings on Tablet (Left rail Settings opens Local/Cloud DB settings instead)
Setup needed: Android tablet (or tablet/expanded layout mode) with an Enterprise Server DB session.
RC8 status: OPEN (new #1) — Impact: When a user is logged into an Enterprise Server database on a tablet, tapping Settings in the left navigation rail opens the Local / Cloud DB settings instead of the active Server DB settings. This means users cannot access or modify Server DB settings on tablets.
Steps
- Open Password Depot on an Android tablet, or use tablet/expanded layout mode.
- Connect and log into an Enterprise Server database.
- Tap the Settings icon/item in the left navigation rail.
- Check whether Server DB Settings opens (vs Local/Cloud DB settings).
- Close or return from Settings; confirm the active Server DB session is preserved.
Expected
- The navigation rail Settings opens the active Server DB settings when connected to an Enterprise Server DB, OR a dedicated Settings / Database Properties (⚙️) icon is available in the Server DB top bar/header (matching the phone mode implementation from AC-746).
- Closing or returning from Settings keeps the user inside the active Server DB session.
Result
Status: ⏭️ SKIP
Comments:
RC8-N2AC-767Sev-2✅ PASS
[Server DB] Support adding and editing additional URLs for entries
Setup needed: Enterprise Server DB; an entry with URL field; local DB or Windows client for comparison.
RC8 status: OPEN (new #2) — Summary: The Enterprise Server (Server DB) entry editor only supports a single URL field. Users cannot add, edit, or delete additional or associated URLs for an entry. Context: This issue occurs when using an Enterprise Server database on Android. Local/Cloud databases already support managing multiple URLs, and the Windows client has this feature as well.
Steps
- Open an entry in the Server DB entry editor.
- Try to add an additional URL.
- Try to edit an additional URL.
- Try to delete an additional URL.
- Compare with the local DB entry editor and the Windows client.
Expected
- Users can add additional URLs to Server DB entries.
- Users can edit additional URLs for Server DB entries.
- Users can delete additional URLs for Server DB entries.
- The Server DB entry editor matches the local database entry editor and Windows client feature parity.
- The URL section supports a list mechanism and a "+" option for managing multiple URLs.
Result
Status: ✅ PASS
Comments:
Part 2 — RC5 NEW BUGS Regression (10)
These 10 RC5 New Bugs were verified PASS in RC8 (RC8 QA Report 2026-10-01, section 3a). Confirm no regression on RC9.
RC5-N2AC-717Sev-2✅ PASS
Switching to standard user offline DB still prompts for SSO login after saving SSO offline DB
Setup needed: A device with an SSO offline DB already saved; a standard-user offline DB available.
RC8 status: PASS — RC8: Verified PASS.
Steps
- Sign in with SSO and save an SSO offline DB.
- Sign out.
- Attempt to open a standard-user offline DB.
- Observe the login prompt (SSO vs standard).
- Try switching back to standard-user login.
Expected
- The client offers standard user login for the standard-user offline DB.
- No SSO prompt is forced.
Result
Status: ✅ PASS
Comments:
RC5-N3AC-732Sev-2✅ PASS
Server certificate confirmation prompt reappears when clicking "Load databases" in "Save offline copy" after already trusting the certificate
Setup needed: Enterprise Server 20; certificate previously trusted.
RC8 status: PASS — RC8: Verified PASS.
Steps
- Sign in to the server and trust the certificate.
- Start "Save offline copy".
- Tap "Load databases".
- Observe whether the certificate confirmation prompt reappears.
Expected
- Certificate is remembered; no repeated confirmation prompt.
- The "Load databases" action proceeds without re-prompting.
Result
Status: ✅ PASS
Comments:
RC5-N4AC-679Sev-2✅ PASS
Home screen: Keep "Another way in" section expanded by default when databases exist
Setup needed: A device with at least one local DB.
RC8 status: PASS — RC8: Verified PASS.
Steps
- Expand the "Another way in" section on the Home screen.
- Create a new local DB.
- Return to the Home screen.
- Check whether the section is still expanded.
Expected
- "Another way in" stays expanded by default when databases exist.
- It only collapses when the user explicitly hides it.
Result
Status: ✅ PASS
Comments:
RC5-N5AC-733Sev-2✅ PASS
[UX] Expand markdown toolbar items in full-screen comment editor instead of keeping them in the overflow dropdown
Setup needed: An entry with a comment field on a device with enough horizontal space (tablet recommended).
RC8 status: PASS — RC8: Verified PASS.
Steps
- Open the comment editor.
- Switch to full-screen mode.
- Observe the markdown/formatting toolbar.
- Compare with the compact/inline view.
Expected
- Full-screen toolbar exposes more (or all) formatting items directly.
- Overflow dropdown is minimized on large screens.
Result
Status: ✅ PASS
Comments:
RC5-N6AC-734Sev-2✅ PASS
Align "Conditional access" tab in Entry editor with Windows client (UI items, warning levels & access triggers)
Setup needed: Entry editor on Android; Windows client for reference; Server 20 with ES-1002 for server path.
RC8 status: PASS — RC8: Verified PASS.
Steps
- Open the Entry editor on Android → Conditional access tab.
- Check the severity radio options (Informational / Major / Critical).
- Select Critical; verify the Verification text input becomes active.
- Test on a Local DB (.pswe).
- Test on an offline copy.
- Test on a Server DB via REST v2 ES-1002.
Expected
- Three severity radio options present and match Windows.
- Verification text input active only when Critical is selected.
- Works on Local DB, offline copy, and Server DB (REST v2 ES-1002).
Result
Status: ✅ PASS
Comments:
RC5-N9AC-738Sev-2✅ PASS
[Support Data] Copy button fails to copy logs under "From the autofill process"
Setup needed: A device with autofill logs present.
RC8 status: PASS — RC8: Verified PASS.
Steps
- Lock the app → tap "Support data…" on the unlock screen.
- Locate the "From the autofill process" section.
- Tap "Copy".
- Paste into a text editor and inspect the content.
Expected
- The full Support Data (including "From the autofill process") is copied.
- No logs after that heading are omitted.
Result
Status: ✅ PASS
Comments:
RC5-N10AC-739Sev-2✅ PASS
[Support Data] Include app version, Android OS version, and default browser version in support data logs
Setup needed: Any device.
RC8 status: PASS — RC8: Verified PASS.
Steps
- Lock the app → tap "Support data…" on the unlock screen.
- Inspect the content.
- Check for: app version, Android OS version, default browser version.
- Tap "Copy" and paste into a text editor to confirm they are present in the copied text.
Expected
- App version, Android OS version, and default browser version appear in the Support Data.
- They are also present in the copied clipboard content.
Result
Status: ✅ PASS
Comments:
RC5-N11AC-698Sev-2✅ PASS
[Tablet][Enterprise] Server DB does not use two-pane (master-detail) layout unlike Local DB
Setup needed: Android tablet (or large-screen device / emulator); both a Local DB and an Enterprise Server DB available.
RC8 status: PASS — RC8: Verified PASS.
Steps
- Launch Password Depot on an Android tablet.
- Open a Local DB (Entries tab) and tap any entry. Observe: two-pane split view.
- Switch to the Enterprise tab and open an Enterprise Server DB.
- Tap any entry from the list in Server DB.
- Observe the layout.
- Rotate the device; observe whether the layout survives.
Expected
- Server DB uses the same two-pane (master-detail) layout as Local DB.
- Entry list stays visible on the left; entry details open on the right.
- Layout survives rotation.
Result
Status: ✅ PASS
Comments:
RC5-N12AC-704Sev-2✅ PASS
[Autofill][Android 14 Tablet] "Setup Autofill" banner remains visible after enabling autofill service and credential provider
Setup needed: Android 14 (API 34) tablet (e.g. T33-F11). Compare with Android 15+ (API 35, e.g. Galaxy S22).
RC8 status: PASS — RC8: Verified PASS.
Steps
- Install a clean build on the Android 14 device (or clear app cache/data).
- Launch the app and log in / open a DB.
- Observe the "Setup Autofill" prompt/banner at the top of the entry list.
- Tap the "Setup Autofill" banner → system configuration screen.
- In Android System Settings: enable Password Depot under Passwords, passkeys & autofill; ensure it is toggled/selected under Additional providers / Credential Manager.
- Switch back / navigate back to Password Depot.
- Observe the banner.
- Repeat on Android 15+ for comparison.
Expected
- App detects that autofill service is enabled upon onResume.
- "Setup Autofill" banner automatically disappears.
- Same behavior on Android 14 and Android 15+.
Result
Status: ✅ PASS
Comments:
RC5-N13AC-707Sev-2✅ PASS
[Security/Settings] Enable lowercase, uppercase, and numbers by default in Master Password Policy
Setup needed: Clean install (or cleared app data), no enterprise-managed settings override.
RC8 status: PASS — RC8: Verified PASS.
Steps
- Fresh install / clear app data.
- Open Settings → Master password policy.
- Observe the default values.
- Create a new database; set a master password that violates the new defaults (e.g. all lowercase, no number).
- Try to change the master password with the same weak password.
Expected
- Min length = 8; Lowercase = ON; Uppercase = ON; Numbers = ON; Special characters = OFF (all by default on clean install).
- Database creation and master password change enforce these defaults unless the user changes them or an enterprise server policy overrides them.
Result
Status: ✅ PASS
Comments:
Part 3 — RC9 Smoke: Google Play Readiness
RC9 is the build that will go to Google Play. This is the smoke pass that must be green before submission. RC8 passed all 7; RC9 must confirm no regression.
RC-1Sev-0✅ PASS
Release build identity and Play Store readiness
Setup needed: A device with Google Play installed.
What to test: Confirm build identity, target API 36, release configuration.
RC8 status: PASS
Steps
- Settings → Version; confirm "20.0.0 RC9 (2009)".
- App info; confirm targetSdkVersion Android 16 (API 36).
- Not debuggable; no debug surface.
- Screenshots/recording blocked.
- Package name matches Play listing.
Expected
- Version line exact; API 36; not debuggable; screenshots blocked; package name correct.
Result
Status: ✅ PASS
Comments:
RC-2Sev-0✅ PASS
First launch on a clean device (no test data)
What to test: Empty start screen, first DB creation, first entry creation end to end.
RC8 status: PASS
Steps
- Uninstall previous build.
- Install RC9 from internal test track.
- Open; confirm empty start screen.
- Create DB; add entry; lock/unlock.
- Force-close and relaunch; confirm locked.
Expected
- Empty start; DB/entry creation works; force-close restarts locked.
Result
Status: ✅ PASS
Comments:
RC-4Sev-0✅ PASS
Privacy policy and data safety
What to test: Privacy policy link present, reachable, matching Data Safety declaration.
RC8 status: PASS
Steps
- Settings → About/Legal; confirm privacy policy link.
- Tap; confirm opens in browser.
- Confirm Data Safety declaration matches app.
Expected
- Link present and reachable; content matches; declaration accurate.
Result
Status: ✅ PASS
Comments:
RC-5Sev-1✅ PASS
Android 16 (API 36) edge-to-edge and 3-button navigation
Setup needed: Android 15/16 device with 3-button navigation.
What to test: Edge-to-edge drawing on Android 15/16 phones with 3-button navigation.
RC8 status: PASS
Steps
- Open app on Android 15/16 with 3-button navigation.
- Check status bar, navigation bar, keyboard.
- Open autofill window and passkey dialogs.
- Rotate.
Expected
- Edge-to-edge correct; no content hidden.
Result
Status: ✅ PASS
Comments:
RC-6Sev-1✅ PASS
All 27 languages shipped in RC9
What to test: All 27 languages listed and switching works.
RC8 status: PASS
Steps
- Settings → App language.
- Confirm 27 languages.
- Switch to three; confirm UI changes.
- Switch back to English.
Expected
- 27 languages listed; switching works without restart.
Result
Status: ✅ PASS
Comments:
RC-7Sev-1✅ PASS
Upgrade from RC8 to RC9 with data kept
Setup needed: Device with RC8 installed and a populated DB.
What to test: Update from RC8 without losing data.
RC8 status: PASS
Steps
- Install RC8; create DB with entries + second-password entry.
- Update to RC9.
- Confirm DB still there and unlocks.
- Confirm entries/second-password/settings intact.
Expected
- Update installs over RC8; data kept.
Result
Status: ✅ PASS
Comments:
RC-8Sev-0✅ PASS
Crash-free cold start and warm start
What to test: Cold/warm start and autofill reconnect do not crash. RC8 passed; RC9 must confirm.
RC8 status: PASS
Steps
- Cold start: force-stop, then open.
- Warm start: background then foreground.
- Reboot device; open again.
- Autofill reconnect: expire server DB session, trigger autofill, tap "Use a local database instead".
- Watch for crash/ANR/freeze.
Expected
- Cold start OK; warm start clean; reboot OK; autofill reconnect no crash.
Result
Status: ✅ PASS
Comments:
Part 4 — Security & MDM
All PASS in RC8; confirm no regression on RC9.
SEC-1Sev-1✅ PASS
Migration path uses the same wrong-password throttle as the unlock screen
RC8 status: PASS
Steps
- Start the migration / import from previous app flow.
- Enter the wrong password several times.
- Observe whether the same throttle as the unlock screen kicks in.
- Enter the correct password after the throttle.
Expected
- Wrong-password throttle applies to the migration path.
- Clear message shown when throttled.
- Correct password still succeeds after throttle.
Result
Status: ✅ PASS
Comments:
SEC-2Sev-1🚫 BLOCKED
MDM bans (export, cloud, autofill, clipboard) enforced at the sink
Setup needed: A device with an MDM profile that bans export / cloud / autofill / clipboard.
RC8 status: PASS
Steps
- With the MDM profile active, try to export a database / entry.
- Try to use cloud sync (WebDAV / Google Drive / HiDrive).
- Try autofill on a login page.
- Try to copy a password to the clipboard.
- Verify each is blocked at the sink (not just hidden in the UI).
Expected
- Export blocked at the file-write sink.
- Cloud blocked at the network sink.
- Autofill blocked at the fill sink.
- Clipboard blocked at the clipboard-write sink.
- No bypass via direct intent / share / external app.
Result
Status: 🚫 BLOCKED
Environment / blocker info: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Comments:
SEC-3Sev-1🚫 BLOCKED
MDM bans enforced in the autofill / passkey process (from round 5)
Setup needed: A device with an MDM profile that bans autofill / clipboard.
RC8 status: PASS
Steps
- With the MDM profile active, trigger autofill in a browser and in an app.
- Trigger a passkey registration / sign-in.
- Verify the bans are enforced inside those processes.
- Try to bypass via the autofill UI or passkey UI.
Expected
- Autofill process enforces the MDM bans.
- Passkey process enforces the MDM bans.
- No bypass from the independent process.
Result
Status: 🚫 BLOCKED
Environment / blocker info: Phone: Pixel 8 Pro, Android 15, Tablet: Pixel Tablet, Android 15
Comments:
SEC-4Sev-1✅ PASS
Tablet: revealing a password no longer wanders to the next entry when selection changes
Setup needed: A tablet / foldable with the two-pane layout.
RC8 status: PASS
Steps
- Open entry A in the detail pane.
- Reveal the password for A.
- Select entry B in the list.
- Verify B does not show A’s plaintext.
- Select back A; verify A’s reveal state is correct.
- Rotate / search / filter / scroll; verify no plaintext leaks.
- Lock and unlock; verify reveal state is reset.
Expected
- Revealed password is bound to its entry.
- Changing selection does not carry plaintext to another entry.
- Rotation/search/filter/scroll do not leak.
- Lock/unlock resets reveal state.
Result
Status: ✅ PASS
Comments:
Part 5 — RC1 Reported Bugs Regression (10 PASS)
These RC1 Reported Bugs passed in RC8. AC-624 (Edge autofill) has been moved to Part 0 because it was reopened. Confirm no regression on RC9.
REV-N1AC-620Sev-2✅ PASS
Autofill: Modifying username after autofill and logging in creates a new entry instead of updating existing entry
RC8 status: PASS
Steps
- Autofill username/password in Chrome.
- Change the username in the form.
- Log in; tap Update when prompted.
- Check: existing entry updated, no new entry created.
Expected
- Existing entry is updated; no new entry is created.
Result
Status: ✅ PASS
Comments:
REV-N2AC-623Sev-2✅ PASS
Recycle Bin: Add button/option to empty or clean recycle bin
RC8 status: PASS
Steps
- Open the recycle bin.
- Look for an "Empty recycle bin" action.
Expected
- A button/menu option empties the whole recycle bin at once.
Result
Status: ✅ PASS
Comments:
REV-N4AC-625Sev-2✅ PASS
Server DB: TOTP field/code is not displayed in entry details view on Android client
RC8 status: PASS
Steps
- Sign in to Enterprise Server 20.
- Open an entry with a TOTP secret.
- Check the entry details view.
Expected
- TOTP field and current code displayed.
Result
Status: ✅ PASS
Comments:
REV-N5AC-626Sev-2✅ PASS
Entry Details: Importance set to "High" is incorrectly displayed as "Low" on Android client
RC8 status: PASS
Steps
- Create/update entry with Importance = High on Windows.
- Open same entry on Android.
- Check the Importance badge.
Expected
- Importance badge reads "High".
Result
Status: ✅ PASS
Comments:
REV-N6AC-627Sev-2✅ PASS
Entry: Warning message configured on Windows client does not pop up when accessing the entry on Android
RC8 status: PASS
Steps
- Configure warning message on Windows for an entry.
- Sync/open DB on Android.
- Open that entry.
Expected
- Warning dialog appears with configured text before details are shown.
Result
Status: ✅ PASS
Comments:
REV-N7AC-628Sev-2✅ PASS
Server DB: Redundant "Expires" field displayed in DETAILS block for Credit Card entries created via Windows Client in ES DB
RC8 status: PASS
Steps
- Create Credit Card entry on Windows in ES DB.
- Open on Android.
- Check DETAILS for redundant Expires.
Expected
- No redundant/empty Expires field.
Result
Status: ✅ PASS
Comments:
REV-N8AC-629Sev-2✅ PASS
Unify entry field/item names across new clients with Windows client
RC8 status: PASS
Steps
- Open a few entry types on Android.
- Compare labels with Windows client.
Expected
- Field/item names match the Windows client wording.
Result
Status: ✅ PASS
Comments:
REV-C1AC-440Sev-2✅ PASS
Android Client becomes slow and laggy when database contains 20,000+ entries
RC8 status: PASS
Steps
- Open a DB with 20,000+ entries.
- Scroll the entry list.
- Search by title.
Expected
Result
Status: ✅ PASS
Comments:
REV-C2AC-430Sev-2✅ PASS
SSPI login mode - User Logon Name Format settings do not match expected behavior for Simple, Domain\sAMAccountName, and UPN modes
RC8 status: PASS
Steps
- Open Enterprise login.
- Try Simple, DOMAIN\user, user@company.com.
- Sign in with each against Server 20 + AD.
Expected
- All three formats behave as expected.
Result
Status: ✅ PASS
Comments:
REV-C3AC-333Sev-2✅ PASS
Better to open a numeric keyboard when input a Service phone field
RC8 status: PASS
Steps
- Open an entry with a Service phone field.
- Focus that field.
Expected
- A numeric keyboard opens.
Result
Status: ✅ PASS
Comments:
Part 6 — Beta21 / RC1 Regression (R18-1 – R18-7)
These bugs were reported in earlier rounds. All PASS in RC8. Re-test on RC9.
R18-1AC-604Sev-0✅ PASS
Key file of the old app — now visible in every key-file prompt
Setup needed: A real 19.x installation with a key-file database.
RC8 status: PASS
Steps
- Install 19.x; create/protect DB with key file.
- Update to RC9; open takeover flow.
- Unlock screen → "Choose key file…".
- Verify old app key files listed.
- Pick correct one; unlock.
- Repeat in autofill window and passkey dialog.
- Change master password and restore.
Expected
- Old key files listed in every key-file prompt; chosen one read for that unlock only.
Result
Status: ✅ PASS
Comments:
R18-2AC-605Sev-3✅ PASS
Key-file wording: "Protected with" vs "Additionally protected with"
RC8 status: PASS
Steps
- Open key-file-only DB; check wording.
- Open password+key-file DB; check wording in same three places.
Expected
- Correct wording in both cases.
Result
Status: ✅ PASS
Comments:
R18-3AC-606Sev-3✅ PASS
Names after the takeover
Setup needed: A real 19.x migration.
RC8 status: PASS
Steps
- Migrate DB from 19.x with long path and extension.
- Check name in DB list.
- Create backup copy; check name.
- Open DB; check header.
Expected
- DB name is file name without folder/extension; backup copies named "<name> (backup copy n)".
Result
Status: ✅ PASS
Comments:
R18-4AC-607Sev-3✅ PASS
Takeover report lists skipped settings by name
Setup needed: A real 19.x installation with an invalid setting.
RC8 status: PASS
Steps
- Migrate from 19.x with at least one invalid setting.
- Open takeover report.
Expected
- Skipped settings listed by name.
Result
Status: ✅ PASS
Comments:
R18-5AC-609Sev-2✅ PASS
WebDAV address with "#" gets its own message
Setup needed: HiDrive account (or similar WebDAV address with "#").
RC8 status: PASS
Steps
- Open "Open from cloud…" / "Storage location & sync".
- Paste browser address of HiDrive web interface (contains "#").
- Observe message.
- After entering username, verify "database.pswe" is NOT stripped.
Expected
- Specific message says what to enter instead.
- database.pswe preserved at end of URL.
Result
Status: ✅ PASS
Comments:
R18-6AC-610Sev-3✅ PASS
Autofill hint names the app’s auto-lock value
RC8 status: PASS
Steps
- Set app auto-lock shorter than reuse window.
- Settings → Autofill & passkeys; find "keep unlocked for …" hint.
Expected
- Hint names auto-lock and shows its value.
Result
Status: ✅ PASS
Comments:
R18-7AC-537 / AC-608Sev-1✅ PASS
Enterprise Server: one-time codes and 2FA against Server 20
Setup needed: Enterprise Server 20 (only).
RC8 status: PASS
Steps
- Sign in to Enterprise Server 20.
- Trigger autofill on a site matching a server entry with one-time code.
- Verify username, password and current one-time code filled.
- Trigger 2FA failure; observe exact reason.
Expected
- Autofill fills username/password/one-time code; 2FA failures report exact reason.
Result
Status: ✅ PASS
Comments:
Part 7 — Core Pass: A1–A10 (Every Tester, Every Device)
Estimated time: 45–60 minutes. Run on every device you test. All PASS in RC8; confirm no regression on RC9.
A1✅ PASS
First Launch & Database Creation
RC8 status: PASS
Steps
- Fresh install (or update): open app.
- Create DB with name and test master password.
- Confirm empty entry list.
- Relaunch.
- Enter master password; confirm unlock.
- Enter wrong master password.
Expected
- Empty list; after relaunch locked; correct password unlocks; wrong password clear error.
Result
Status: ✅ PASS
Comments:
A2✅ PASS
Entries of Several Types
RC8 status: PASS
Steps
- Create password entry, credit card (PIN/CVV), identity, information, protected custom field.
- While typing secret fields, check keyboard.
- Open detail view for each.
- Edit each and re-save.
- Windows interop: create encrypted file on Windows, verify visible on Android.
Expected
- Secret fields use password keyboard; detail view readable; nothing lost after edit; encrypted file visible on Android.
Result
Status: ✅ PASS
Comments:
A3✅ PASS
Folders, Search, Trash
RC8 status: PASS
Steps
- Create two folders.
- Move entries.
- Search by title, username, URL.
- Delete entry (move to trash).
- Restore from recycle bin.
Expected
- All operations complete; restored entry in original location.
Result
Status: ✅ PASS
Comments:
A4✅ PASS
Locking
RC8 status: PASS
Steps
- Background and return quickly.
- Stay away past auto-lock.
- Force-close from Recents.
- Relaunch.
Expected
- Quick background stays open; after timeout locked; after force-close next start locked.
Result
Status: ✅ PASS
Comments:
A5✅ PASS
Biometric Unlock + Invalidation
RC8 status: PASS
Steps
- Enable Settings → Security → Biometric unlock.
- Lock DB.
- Unlock with fingerprint/face.
- Enroll additional fingerprint in Android settings.
- Return to app.
Expected
- Biometric unlock works; after new fingerprint app refuses biometrics with explanation; can re-enable.
Result
Status: ✅ PASS
Comments:
A6✅ PASS
Clipboard
RC8 status: PASS
Steps
- Copy password from detail view.
- Check countdown notification.
- Paste in another app.
- Wait 30s; attempt paste again.
- Try "Clear now".
Expected
- Countdown appears; paste within 30s; after 30s no paste; "Clear now" immediate.
Result
Status: ✅ PASS
Comments:
A7✅ PASS
Autofill in Your Daily Browser
Note: Chrome 131+ extra step: Chrome → Settings → Autofill services → "Autofill using another service" → restart Chrome.
RC8 status: PASS
Steps
- Enable Settings → Autofill service.
- Settings → Autofill test; confirm suggestion.
- Navigate to test login page.
- Verify suggestion.
- Fill with Password Depot.
- Log in with new credential typed manually; confirm save/update prompt.
- Negative check: look-alike domain; entry NOT offered.
Expected
- Suggestion on matching domain; save/update works; no suggestion for non-matching.
Result
Status: ✅ PASS
Comments:
A8✅ PASS
Autofill in One App
RC8 status: PASS
Steps
- Open any app with login screen (test account).
- Trigger autofill.
Expected
- Autofill works or cleanly offers nothing — no crash, no wrong entry.
Result
Status: ✅ PASS
Comments:
A9✅ PASS
Appearance, Language, Rotation, Tablet
RC8 status: PASS
Steps
- Switch appearance dark → light → system.
- Switch app language DE ↔ EN.
- Rotate device while unlocked.
- (Tablet/foldable) Verify two-pane layout.
Expected
- Switches work without restart; rotation preserves state; two-pane correct on tablets.
Result
Status: ✅ PASS
Comments:
A10✅ PASS
Stability & Error Visibility
What to test: Any crash, freeze, or silently swallowed error is a top report.
RC8 status: PASS
Steps
- If any occur, open Support data immediately.
- Copy version line and events.
- File Jira Bug Sev-0 with support data.
Expected
- No crashes, freezes, or silently swallowed errors.
Result
Status: ✅ PASS
Comments:
Part 8 — Focus Blocks C1–C11
All PASS in RC8; confirm no regression on RC9.
C1✅ PASS
TOTP
Setup needed: A test account with 2FA/TOTP and a reference authenticator app.
RC8 status: PASS
Steps
- Add TOTP secret via entry editor.
- Use "Scan QR code" (camera/photo).
- Compare 6-digit code with reference authenticator for ≥3 periods.
- With autofill: confirm code offered only into one-time-code field.
Expected
- Codes match for ≥3 periods; code offered only into OTP fields.
Result
Status: ✅ PASS
Comments:
C2✅ PASS
Passkeys (Android 14+)
Setup needed: Android 14+, screen lock enabled. Test site: https://webauthn.io
RC8 status: PASS
Steps
- Settings → Passkey provider → Password Depot; verify "Enabled".
- Register a new passkey on webauthn.io.
- Sign in with the passkey.
- Move passkey entry to trash.
- Attempt sign-in → expect "No matching passkey".
- Restore passkey entry.
- Attempt sign-in again → works.
Expected
- All steps behave as described.
Result
Status: ✅ PASS
Comments:
C3✅ PASS
WebDAV Sync
Setup needed: A real Nextcloud and/or Apache WebDAV server over HTTPS.
RC8 status: PASS
Steps
- Link WebDAV server.
- Initial DB upload.
- Edit entry on Android; sync; verify on Windows.
- Edit same entry on both simultaneously.
- Sync from Android.
Expected
- Initial upload succeeds; concurrent edit → conflicted copy on Android.
Result
Status: ✅ PASS
Comments:
C4✅ PASS
Windows Interop
Setup needed: Windows Password Depot 19 and same DB accessible on both.
RC8 status: PASS
Steps
- Open same .pswe alternately in Windows PD 19 and Android.
- Verify umlauts/emoji, folders, attachments, TAN lists, entry history, custom icons, second-password entry survive both directions.
- Set expiry date on Android; open in Windows; confirm date preserved.
Expected
- All content survives both directions unchanged.
Result
Status: ✅ PASS
Comments:
C5✅ PASS
Attachments
RC8 status: PASS
Steps
- Attach photo (few MB); reopen and export.
- Attach PDF (few MB); reopen and export.
- Attempt to attach file over 25 MB.
Expected
- Photo/PDF attach, export, open correctly; >25 MB refused with clear message, no crash.
Result
Status: ✅ PASS
Comments:
C6✅ PASS
Multi-Database & Master Password Change
What to test: App copy of every DB lives in app private storage; "on this device" DB has no external file.
RC8 status: PASS
Steps
- Create second DB; switch between both.
- Export copy; open via "Open database file…".
- Remove THAT entry from app — file in Downloads must still exist — and open again.
- Change master password of test DB.
- Attempt unlock with old password.
Expected
- Switching works; "Remove from app" does not delete external file; old password rejected.
Result
Status: ✅ PASS
Comments:
C7✅ PASS
Backup & Restore
RC8 status: PASS
Steps
- Databases & sync → Backup copies; create backup.
- Make changes.
- Restore earlier backup.
- Wrong password during restore; check throttle and message.
- Correct password; confirm restore.
- Attempt restore of corrupted backup.
Expected
- Correct password restores; current state saved before restore; wrong password throttle + message; corrupted backup refused, active DB untouched.
Result
Status: ✅ PASS
Comments:
C8✅ PASS
Enterprise Thin Client
Setup needed: Office test server (Enterprise Server 20).
RC8 status: PASS
Steps
- App → "Enterprise server…".
- Enter address/port; log in.
- First connect: verify TLS fingerprint dialog.
- Browse and search entries.
- Edit entry and save.
Expected
- TLS fingerprint dialog first connect; login succeeds; browse/search/edit work.
Result
Status: ✅ PASS
Comments:
C9✅ PASS
Enterprise Offline Copy
Setup needed: Enterprise Server 20, TCP port 25020, DB with offline right granted.
RC8 status: PASS
Steps
- Sign in; tap "Save offline copy…".
- Enter server password.
- Tap "Load databases" — confirm TLS fingerprint once.
- Pick DB; confirm copy saved.
- Sign out; tap "Open offline copy".
- Create/edit entry offline; note waiting-changes counter.
- Settings → Sync… → "Send changes to the server".
Expected
- All steps behave as described.
Result
Status: ✅ PASS
Comments:
C10✅ PASS
Enterprise Single Sign-On (OpenID Connect / Entra ID)
Setup needed: Enterprise Server 20 with configured OIDC or Entra ID provider.
RC8 status: PASS
Steps
- Choose "Single sign-on (OpenID Connect / Entra ID)"; tap "Connect".
- Complete sign-in in browser.
- Sign out; use "Sign in with a different account".
- Start sign-in and cancel in browser.
- Sign in with account server does not know.
Expected
- All scenarios behave as described.
Result
Status: ✅ PASS
Comments:
C11✅ PASS
Hand-Over of Previous-App Offline Changes
Setup needed: Enterprise Server 20, TCP port 25020.
RC8 status: PASS
Steps
- Start with previous Password Depot for Android installed and Enterprise DB with unsent offline changes.
- Update to RC9; open "Import from previous app".
- Verify report names number of unsent changes.
- Tap "Send to the server…".
- Confirm note disappears and changes on server.
Expected
- All steps behave as described.
Result
Status: ✅ PASS
Comments:
5 · Device Matrix Contribution
| Dimension | Variant | Covered | Notes |
|---|
| Keyboard | Gboard | ✅ | |
| Keyboard | Samsung Keyboard | ✅ | |
| Keyboard | SwiftKey | ✅ | |
| Browser | Chrome | ✅ | |
| Browser | Edge | ✅ | |
| Browser | Firefox | ✅ | |
| Browser | Samsung Internet | ❌ | |
| Autofill style | Android 11+ inline chips | ✅ | |
| Autofill style | Android ≤13 dropdown | ✅ | |
| Clipboard | Samsung clipboard behavior | ✅ | |
| Clipboard | Pixel clipboard behavior | ✅ | |
| Clipboard | Xiaomi clipboard behavior | n/a | |
| Biometrics | Fingerprint | ✅ | |
| Biometrics | Face unlock | ✅ | |
| Biometrics | Both enrolled | ✅ | |
| OEM quirks | Xiaomi/HyperOS battery saver — auto-lock reliable? | n/a | |
| OEM quirks | Samsung battery saver — session killed mid-edit? | ✅ | |
| Form factor | Phone | ✅ | |
| Form factor | Tablet (≥ 600 dp) | ✅ | |
| Form factor | Foldable | n/a | |
| Storage | FTPS / FTPES | ✅ | |
| Storage | HiDrive | ✅ | |
| Migration | 19.x migration with key-file database | ✅ | |
| RC9 Smoke | Google Play internal test track install | ✅ | |
6 · Reporting Reference
| Jira Project | Android Client (AC) |
|---|
| Affects Version | 20.0.0 |
|---|
| Build line | 20.0.0 RC9 (2009) |
|---|
| Release | RC9 · Google Play submission pending |
|---|
| Severity 0 | crash · data loss · lock-out |
|---|
| Severity 1 | feature wrong or unusable |
|---|
| Severity 2 | wrong, has a workaround |
|---|
| Severity 3 | visual / text |
|---|
Support data: lock the app → tap "Support data…" on the unlock screen.