# 1. Affiliate Login — Test Cases

User Type: **Affiliate**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: affiliate_login.md — every feature, sub-feature, and rule covered

## Test Execution Policy

- Zero tolerance: any deviation from the documented behavior is a defect.
- Every failed test is logged with a Bug ID, the feature, the sub-feature, the expected vs actual result, and the severity; 100% of bugs are fixed before the group passes.
- 100% pass rate is required for the group to be marked complete.

## Coverage Matrix

| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 1.1 | Sign in with registered email and password | TC-AF-1-01-001 |
| 1.1 | Credential verification | TC-AF-1-01-002 |
| 1.1 | Access to the affiliate portal on success | TC-AF-1-01-003 |
| 1.1 | Error message on invalid credentials | TC-AF-1-01-004 |
| 1.1 | Account lockout after repeated failed attempts | TC-AF-1-01-005 |
| 1.1 | Login available on web and mobile | TC-AF-1-01-006 |
| 1.1 | Login event logging (success, failure) | TC-AF-1-01-007 |
| 1.1 | Audit logging of the email and password login | TC-AF-1-01-008 |
| 1.1 | Rule: The credentials are the registered email and password. | TC-AF-1-01-001 |
| 1.1 | Rule: An error message is shown on invalid credentials. | TC-AF-1-01-002 |
| 1.1 | Rule: The account is locked after repeated failed attempts. | TC-AF-1-01-003 |
| 1.1 | Rule: Login events (success, failure) are logged with the account and the timestamp. | TC-AF-1-01-004 |
| 1.1 | Rule: The email and password login is audit-logged with the account and the timestamp. | TC-AF-1-01-005 |
| 1.2 | Request an OTP to the registered email or phone | TC-AF-1-01-009 |
| 1.2 | Enter the OTP to sign in | TC-AF-1-01-010 |
| 1.2 | OTP verification | TC-AF-1-01-011 |
| 1.2 | OTP is single-use | TC-AF-1-01-012 |
| 1.2 | OTP expires after a short period | TC-AF-1-01-013 |
| 1.2 | Resend OTP with a cooldown | TC-AF-1-01-014 |
| 1.2 | Login available on web and mobile | TC-AF-1-01-015 |
| 1.2 | Login event logging (requested, verified) | TC-AF-1-01-016 |
| 1.2 | Audit logging of the one-time password login | TC-AF-1-01-017 |
| 1.2 | Rule: The OTP is sent to the registered email or phone. | TC-AF-1-01-009 |
| 1.2 | Rule: The OTP is single-use. | TC-AF-1-01-010 |
| 1.2 | Rule: The OTP expires after a short period. | TC-AF-1-01-011 |
| 1.2 | Rule: A resend has a cooldown. | TC-AF-1-01-012 |
| 1.2 | Rule: Login events (requested, verified) are logged with the account and the timestamp. | TC-AF-1-01-013 |
| 1.2 | Rule: The one-time password login is audit-logged with the account and the timestamp. | TC-AF-1-01-014 |
| 1.3 | Sign in with a supported social account | TC-AF-1-01-018 |
| 1.3 | Social provider authorization | TC-AF-1-01-019 |
| 1.3 | Account creation or linking on first social login | TC-AF-1-01-020 |
| 1.3 | Access to the affiliate portal on success | TC-AF-1-01-021 |
| 1.3 | Social account unlink option | TC-AF-1-01-022 |
| 1.3 | Login available on web and mobile | TC-AF-1-01-023 |
| 1.3 | Login event logging (authorized, linked) | TC-AF-1-01-024 |
| 1.3 | Audit logging of the social login | TC-AF-1-01-025 |
| 1.3 | Rule: The social login uses a supported provider. | TC-AF-1-01-018 |
| 1.3 | Rule: The account is created or linked on first social login. | TC-AF-1-01-019 |
| 1.3 | Rule: The social account can be unlinked. | TC-AF-1-01-020 |
| 1.3 | Rule: Login events (authorized, linked) are logged with the account and the timestamp. | TC-AF-1-01-021 |
| 1.3 | Rule: The social login is audit-logged with the account and the timestamp. | TC-AF-1-01-022 |

## 1.1 Email and Password Login

### TC-AF-1-01-001 — Sign in with registered email and password
**Type:** Positive
**Covers:** 1.1 → Sign in with registered email and password; Rule: The credentials are the registered email and password.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Sign in with registered email and password.
2. Observe the result and verify the full behavior: Sign in with registered email and password.
**Expected Result:** Sign in with registered email and password — delivered exactly as documented.
**Priority:** Critical

### TC-AF-1-01-002 — Credential verification
**Type:** Positive
**Covers:** 1.1 → Credential verification; Rule: An error message is shown on invalid credentials.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Credential verification.
2. Observe the result and verify the full behavior: Credential verification.
**Expected Result:** Credential verification — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-003 — Access to the affiliate portal on success
**Type:** Positive
**Covers:** 1.1 → Access to the affiliate portal on success; Rule: The account is locked after repeated failed attempts.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Access to the affiliate portal on success.
2. Observe the result and verify the full behavior: Access to the affiliate portal on success.
**Expected Result:** Access to the affiliate portal on success — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-004 — Error message on invalid credentials
**Type:** Edge
**Covers:** 1.1 → Error message on invalid credentials; Rule: Login events (success, failure) are logged with the account and the timestamp.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Error message on invalid credentials.
2. Observe the result and verify the full behavior: Error message on invalid credentials.
**Expected Result:** Error message on invalid credentials — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-005 — Account lockout after repeated failed attempts
**Type:** Positive
**Covers:** 1.1 → Account lockout after repeated failed attempts; Rule: The email and password login is audit-logged with the account and the timestamp.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Account lockout after repeated failed attempts.
2. Observe the result and verify the full behavior: Account lockout after repeated failed attempts.
**Expected Result:** Account lockout after repeated failed attempts — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-006 — Login available on web and mobile
**Type:** Positive
**Covers:** 1.1 → Login available on web and mobile
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Login available on web and mobile.
2. Observe the result and verify the full behavior: Login available on web and mobile.
**Expected Result:** Login available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-007 — Login event logging (success, failure)
**Type:** Positive
**Covers:** 1.1 → Login event logging (success, failure)
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Login event logging (success, failure).
2. Observe the result and verify the full behavior: Login event logging (success, failure).
**Expected Result:** Login event logging (success, failure) — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-008 — Audit logging of the email and password login
**Type:** Positive
**Covers:** 1.1 → Audit logging of the email and password login
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, perform the email and password login action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The email and password login action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical


## 1.2 One-Time Password (OTP) Login

### TC-AF-1-01-009 — Request an OTP to the registered email or phone
**Type:** Positive
**Covers:** 1.2 → Request an OTP to the registered email or phone; Rule: The OTP is sent to the registered email or phone.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Request an OTP to the registered email or phone.
2. Observe the result and verify the full behavior: Request an OTP to the registered email or phone.
**Expected Result:** Request an OTP to the registered email or phone — delivered exactly as documented.
**Priority:** Critical

### TC-AF-1-01-010 — Enter the OTP to sign in
**Type:** Positive
**Covers:** 1.2 → Enter the OTP to sign in; Rule: The OTP is single-use.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Enter the OTP to sign in.
2. Observe the result and verify the full behavior: Enter the OTP to sign in.
**Expected Result:** Enter the OTP to sign in — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-011 — OTP verification
**Type:** Positive
**Covers:** 1.2 → OTP verification; Rule: The OTP expires after a short period.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: OTP verification.
2. Observe the result and verify the full behavior: OTP verification.
**Expected Result:** OTP verification — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-012 — OTP is single-use
**Type:** Edge
**Covers:** 1.2 → OTP is single-use; Rule: A resend has a cooldown.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: OTP is single-use.
2. Observe the result and verify the full behavior: OTP is single-use.
**Expected Result:** OTP is single-use — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-013 — OTP expires after a short period
**Type:** Edge
**Covers:** 1.2 → OTP expires after a short period; Rule: Login events (requested, verified) are logged with the account and the timestamp.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: OTP expires after a short period.
2. Observe the result and verify the full behavior: OTP expires after a short period.
**Expected Result:** OTP expires after a short period — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-014 — Resend OTP with a cooldown
**Type:** Edge
**Covers:** 1.2 → Resend OTP with a cooldown; Rule: The one-time password login is audit-logged with the account and the timestamp.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Resend OTP with a cooldown.
2. Observe the result and verify the full behavior: Resend OTP with a cooldown.
**Expected Result:** Resend OTP with a cooldown — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-015 — Login available on web and mobile
**Type:** Positive
**Covers:** 1.2 → Login available on web and mobile
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Login available on web and mobile.
2. Observe the result and verify the full behavior: Login available on web and mobile.
**Expected Result:** Login available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-016 — Login event logging (requested, verified)
**Type:** Positive
**Covers:** 1.2 → Login event logging (requested, verified)
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Login event logging (requested, verified).
2. Observe the result and verify the full behavior: Login event logging (requested, verified).
**Expected Result:** Login event logging (requested, verified) — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-017 — Audit logging of the one-time password login
**Type:** Positive
**Covers:** 1.2 → Audit logging of the one-time password login
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, perform the one-time password login action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The one-time password login action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical


## 1.3 Social Login

### TC-AF-1-01-018 — Sign in with a supported social account
**Type:** Positive
**Covers:** 1.3 → Sign in with a supported social account; Rule: The social login uses a supported provider.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Sign in with a supported social account.
2. Observe the result and verify the full behavior: Sign in with a supported social account.
**Expected Result:** Sign in with a supported social account — delivered exactly as documented.
**Priority:** Critical

### TC-AF-1-01-019 — Social provider authorization
**Type:** Positive
**Covers:** 1.3 → Social provider authorization; Rule: The account is created or linked on first social login.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Social provider authorization.
2. Observe the result and verify the full behavior: Social provider authorization.
**Expected Result:** Social provider authorization — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-020 — Account creation or linking on first social login
**Type:** Positive
**Covers:** 1.3 → Account creation or linking on first social login; Rule: The social account can be unlinked.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Account creation or linking on first social login.
2. Observe the result and verify the full behavior: Account creation or linking on first social login.
**Expected Result:** Account creation or linking on first social login — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-021 — Access to the affiliate portal on success
**Type:** Positive
**Covers:** 1.3 → Access to the affiliate portal on success; Rule: Login events (authorized, linked) are logged with the account and the timestamp.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Access to the affiliate portal on success.
2. Observe the result and verify the full behavior: Access to the affiliate portal on success.
**Expected Result:** Access to the affiliate portal on success — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-022 — Social account unlink option
**Type:** Positive
**Covers:** 1.3 → Social account unlink option; Rule: The social login is audit-logged with the account and the timestamp.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Social account unlink option.
2. Observe the result and verify the full behavior: Social account unlink option.
**Expected Result:** Social account unlink option — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-023 — Login available on web and mobile
**Type:** Positive
**Covers:** 1.3 → Login available on web and mobile
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Login available on web and mobile.
2. Observe the result and verify the full behavior: Login available on web and mobile.
**Expected Result:** Login available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-024 — Login event logging (authorized, linked)
**Type:** Positive
**Covers:** 1.3 → Login event logging (authorized, linked)
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Login event logging (authorized, linked).
2. Observe the result and verify the full behavior: Login event logging (authorized, linked).
**Expected Result:** Login event logging (authorized, linked) — delivered exactly as documented.
**Priority:** High

### TC-AF-1-01-025 — Audit logging of the social login
**Type:** Positive
**Covers:** 1.3 → Audit logging of the social login
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, perform the social login action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The social login action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical
