# Login page — test cases

## Sign in (AUTH)

| ID | Journey | Preconditions | Steps | Expected result | WEB | AND | IOS |
|---|---|---|---|---|---|---|---|
| AUTH-01 | Sign in with email and password | Signed out. An existing, verified account | 1. Open the sign-in screen. 2. Enter the account's email and password. 3. Tap Sign in. | The home screen opens with the account's name or picture showing. Reloading the page or reopening the app keeps you signed in. | | | |
| AUTH-02 | A wrong password is refused clearly | Signed out. An existing account | 1. Enter the account's email and a wrong password. 2. Tap Sign in. | A message says the email or password is wrong, without saying which. The email stays filled in and the password field is cleared. You are not signed in. | | | |
| AUTH-03 | An email with no account gets the same message | Signed out. No account exists for the email you will use | 1. Enter the unknown email and any password. 2. Tap Sign in. | The same message as for a wrong password, in the same place and after about the same wait. Nothing on screen says the account does not exist. | | | |
| AUTH-04 | Empty fields are caught before sending | Signed out | 1. Leave both fields empty and tap Sign in. 2. Fill in only the email and tap Sign in. | Each time, a message beside the empty field says it is required, and nothing else happens. Whatever was typed stays in place. | | | |
| AUTH-05 | A saved password fills in and works | Signed out. The account's password saved in the browser's or the phone's password manager | 1. Open the sign-in screen. 2. Tap the email field and choose the saved account. 3. Tap Sign in. | The password manager offers the account and fills both fields, and signing in works. After a password change, the browser or phone offers to update the saved password. | | | |
| AUTH-06 | No connection when signing in | Signed out. Wi-Fi and mobile data off | 1. Enter a correct email and password. 2. Tap Sign in. 3. Turn the connection back on and tap Sign in again. | A message says there is no connection, not a wrong-password message and not an endless spinner. The fields keep what was typed. The second attempt signs you in. | | | |

## Password field and lockout (LOCK)

| ID | Journey | Preconditions | Steps | Expected result | WEB | AND | IOS |
|---|---|---|---|---|---|---|---|
| LOCK-01 | Show and hide the password | Signed out | 1. Type a password. 2. Tap Show password. 3. Type two more characters. 4. Tap Hide password. | The password is readable after Show and hidden again after Hide. Nothing typed is lost, and typing carries on where it left off. The password field never offers spelling suggestions. | | | |
| LOCK-02 | Repeated wrong passwords are slowed down | Signed out. An existing account. You know how many failed attempts your app allows | 1. Enter a wrong password and tap Sign in, one more time than allowed. 2. Enter the correct password and tap Sign in. 3. Wait until the time the message gives has passed. 4. Sign in with the correct password. | After the limit, a message says to wait or to check your email, and for how long. The correct password is also refused until then. After the wait it signs you in. The message never confirms whether the account exists. | | | |

## Staying signed in (SESS)

| ID | Journey | Preconditions | Steps | Expected result | WEB | AND | IOS |
|---|---|---|---|---|---|---|---|
| SESS-01 | Remember me keeps you signed in | Signed out. A browser set not to reopen the last session on start | 1. Tick Remember me and sign in. 2. Quit the browser completely. 3. Open it and go to the site. | You are still signed in, without entering the password. | | N/A | N/A |
| SESS-02 | Without Remember me, quitting the browser signs you out | Signed out. A browser set not to reopen the last session on start | 1. Leave Remember me unticked and sign in. 2. Quit the browser completely. 3. Open it and go to the site. | The sign-in screen appears. Opening a page that needs an account sends you to sign in. | | N/A | N/A |
| SESS-03 | The app stays signed in after it is closed | Signed in on the app | 1. Close the app completely from the app switcher. 2. Open it again. 3. Restart the phone and open the app again. | Each time the app opens signed in, without asking for the password. | N/A | | |
| SESS-04 | Signing out cannot be undone with Back | Signed in, on a screen that shows account details | 1. Tap Sign out. 2. Press Back, or swipe back. 3. Reload the page, or reopen the app. | The sign-in screen stays. Going back does not show the account's details, even briefly, and nothing can be done as the signed-out account. | | | |
| SESS-05 | Changing the password signs out other devices | Signed in on two devices with the same account | 1. On device A, change the password. 2. On device B, open any screen that loads account data. | Device A stays signed in. Device B is sent to the sign-in screen, and the old password no longer works there. | | | |

## Forgot password (RESET)

| ID | Journey | Preconditions | Steps | Expected result | WEB | AND | IOS |
|---|---|---|---|---|---|---|---|
| RESET-01 | Reset a forgotten password from the sign-in screen | Signed out. An existing account whose inbox you can open | 1. Tap Forgot password. 2. Enter the email and submit. 3. Open the link in the email. 4. Set a new password. 5. Sign in with the new password. 6. Sign out and sign in with the old password. | The email arrives within a minute. The new password signs you in. The old password gets the usual wrong-password message. | | | |
| RESET-02 | A reset link works once | A reset link that has already been used to set a new password | 1. Open the same link again. | A page says the link has been used or has expired, with a way to ask for a new one. The password does not change. | | | |
| RESET-03 | A reset for an unknown email gives nothing away | Signed out. No account exists for the email | 1. Tap Forgot password. 2. Enter the unknown email and submit. | The same confirmation as for a real account. No email arrives, and nothing on screen says the account does not exist. | | | |

## Single sign-on and social sign-in (SSO)

| ID | Journey | Preconditions | Steps | Expected result | WEB | AND | IOS |
|---|---|---|---|---|---|---|---|
| SSO-01 | Continue with Google creates an account | Signed out. A Google account that has never used the app | 1. Tap Continue with Google. 2. Choose the Google account and allow access. 3. Sign out and continue with Google again. | You come back to the app signed in, not to a stray browser tab. The name and email come from the Google account. The second time signs in to the same account rather than making a new one. | | | |
| SSO-02 | Cancelling the provider's screen is harmless | Signed out | 1. Tap Continue with Google. 2. Close or cancel the provider's screen. 3. Tap Continue with Google again. | Step 2 returns you to the sign-in screen with no error page and no half-made account. Step 3 opens the provider's screen again as normal. | | | |
| SSO-03 | Sign in with Apple using Hide My Email | Signed out. An Apple account that has never used the app | 1. Tap Sign in with Apple. 2. Choose Hide My Email and continue. 3. Sign out and sign in with Apple again. | The account is created with the private relay address, and the app does not demand a real email to continue. Signing in again lands on the same account. Emails the app sends reach the Apple account's inbox. | | | |
| SSO-04 | Social sign-in with an email that already has a password account | Signed out. An account made with email and password, and a Google account with the same email | 1. Tap Continue with Google. 2. Choose that Google account. | You end up in the existing account, or a message explains how to link the two. No second account is created for the same email. | | | |

## Two-step verification (MFA)

| ID | Journey | Preconditions | Steps | Expected result | WEB | AND | IOS |
|---|---|---|---|---|---|---|---|
| MFA-01 | A code from an authenticator app signs you in | Signed out. An account with two-step verification set up in an authenticator app | 1. Sign in with email and password. 2. Enter the current code from the authenticator app. | The code screen appears after the password, and the code signs you in. Before the code is entered, no screen past the code screen can be opened. | | | |
| MFA-02 | A wrong or expired code is refused | Signed out. An account with two-step verification | 1. Sign in with email and password. 2. Enter a wrong code. 3. Enter a code that has just expired. 4. Enter the current code. | Steps 2 and 3 show a message that the code is wrong or has expired, and you stay on the code screen without retyping the password. Step 4 signs you in. | | | |
| MFA-03 | A code by text message or email can be resent | Signed out. An account that receives codes by text message or email | 1. Sign in with email and password. 2. Tap Resend code. 3. Enter the newest code. | The code arrives within a minute. Resend is unavailable for a short wait, then sends a new code, and the newest code works. On a phone, a code sent by text is offered above the keyboard. | | | |

## Accessibility (ACC)

| ID | Journey | Preconditions | Steps | Expected result | WEB | AND | IOS |
|---|---|---|---|---|---|---|---|
| ACC-01 | Sign in with the keyboard alone | Signed out. A computer with a keyboard and no mouse | 1. Press Tab from the top of the page. 2. Fill in the email and password. 3. Press Enter. | Tab moves in order through email, password, Show password, Remember me, Sign in and Forgot password, with a visible outline on each. Enter signs you in. | | N/A | N/A |
| ACC-02 | Sign in with a screen reader | Signed out. VoiceOver, TalkBack, or a screen reader on the computer, turned on | 1. Move through the sign-in screen. 2. Enter a wrong password and sign in. 3. Enter the right one and sign in. | Each field is read out by its label, not only its placeholder. Show password is read as a button with its state. The error is read out when it appears. Signing in works without looking at the screen. | | | |
| ACC-03 | Large text and zoom keep the screen usable | Signed out. Text size set to the largest, or the browser zoomed to 200% | 1. Open the sign-in screen. 2. Sign in. | No label or button is cut off or overlapping. Sign in and Forgot password can be reached by scrolling, and signing in works. | | | |

## On a phone (MOB)

| ID | Journey | Preconditions | Steps | Expected result | WEB | AND | IOS |
|---|---|---|---|---|---|---|---|
| MOB-01 | The right keyboard, and nothing hidden behind it | Signed out, on a small phone | 1. Tap the email field. 2. Tap Next. 3. Type the password and tap Go or Done. | The email keyboard shows the @ key and does not capitalise the first letter. Next moves to the password field. Go or Done signs you in. The Sign in button and any error are not hidden behind the keyboard. | | | |
| MOB-02 | Turn on and use face or fingerprint sign-in | Signed in. Face or fingerprint unlock set up on the phone | 1. Turn on biometric sign-in in the app. 2. Close the app completely and open it. 3. Look at the phone or touch the sensor. | The app asks before turning it on, then opens signed in after a face or fingerprint match, without the password. | N/A | | |
| MOB-03 | A failed face or fingerprint falls back to the password | Biometric sign-in turned on in the app | 1. Open the app. 2. Use an unregistered finger, or cover the camera, until the phone gives up, or tap Cancel. | The app offers to sign in with the password instead. It does not crash, repeat the prompt endlessly, or sign you in. | N/A | | |
| MOB-04 | Leaving to fetch a code keeps your place | Signed out, on a phone. An account that receives a sign-in code by email | 1. Sign in with email and password. 2. On the code screen, switch to the email app and copy the code. 3. Switch back and paste it. | The app or page is still on the code screen, not back at the start. The pasted code is accepted and signs you in. | | | |
