# 3. Password & Security Management — Test Cases

User Type: **Affiliate**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: password_security_management.md — every feature, sub-feature, and rule covered

## Test Execution Policy

- Zero tolerance: any deviation from the documented behavior is a defect.
- Every failed test is logged with a Bug ID, the feature, the sub-feature, the expected vs actual result, and the severity; 100% of bugs are fixed before the group passes.
- 100% pass rate is required for the group to be marked complete.

## Coverage Matrix

| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 3.1 | Enter the current password | TC-AF-1-03-001 |
| 3.1 | Enter a new password | TC-AF-1-03-002 |
| 3.1 | New password strength validation | TC-AF-1-03-003 |
| 3.1 | Password updated on success | TC-AF-1-03-004 |
| 3.1 | Other active sessions signed out on change | TC-AF-1-03-005 |
| 3.1 | Change confirmation | TC-AF-1-03-006 |
| 3.1 | Change available on web and mobile | TC-AF-1-03-007 |
| 3.1 | Change event logging (initiated, completed) | TC-AF-1-03-008 |
| 3.1 | Audit logging of the change password | TC-AF-1-03-009 |
| 3.1 | Rule: The current password is required. | TC-AF-1-03-001 |
| 3.1 | Rule: The new password strength is validated. | TC-AF-1-03-002 |
| 3.1 | Rule: Other active sessions are signed out on change. | TC-AF-1-03-003 |
| 3.1 | Rule: Change events (initiated, completed) are logged with the account and the timestamp. | TC-AF-1-03-004 |
| 3.1 | Rule: The change password is audit-logged with the account and the timestamp. | TC-AF-1-03-005 |
| 3.2 | Enter the registered email to start a reset | TC-AF-1-03-010 |
| 3.2 | Reset link sent to the email | TC-AF-1-03-011 |
| 3.2 | Set a new password via the link | TC-AF-1-03-012 |
| 3.2 | Reset link is single-use | TC-AF-1-03-013 |
| 3.2 | Reset link expires | TC-AF-1-03-014 |
| 3.2 | Resend reset link with a cooldown | TC-AF-1-03-015 |
| 3.2 | Reset available on web and mobile | TC-AF-1-03-016 |
| 3.2 | Reset event logging (requested, completed) | TC-AF-1-03-017 |
| 3.2 | Audit logging of the forgot password | TC-AF-1-03-018 |
| 3.2 | Rule: The reset is started with the registered email. | TC-AF-1-03-010 |
| 3.2 | Rule: The reset link is single-use and expires. | TC-AF-1-03-011 |
| 3.2 | Rule: A resend has a cooldown. | TC-AF-1-03-012 |
| 3.2 | Rule: Reset events (requested, completed) are logged with the account and the timestamp. | TC-AF-1-03-013 |
| 3.2 | Rule: The forgot password is audit-logged with the account and the timestamp. | TC-AF-1-03-014 |
| 3.3 | Enable two-factor authentication | TC-AF-1-03-019 |
| 3.3 | One-time code at login (authenticator or SMS) | TC-AF-1-03-020 |
| 3.3 | Backup codes for recovery | TC-AF-1-03-021 |
| 3.3 | Disable two-factor authentication | TC-AF-1-03-022 |
| 3.3 | Reconfigure the 2FA method | TC-AF-1-03-023 |
| 3.3 | 2FA status shown | TC-AF-1-03-024 |
| 3.3 | 2FA available on web and mobile | TC-AF-1-03-025 |
| 3.3 | 2FA event logging (enabled, disabled, code verified) | TC-AF-1-03-026 |
| 3.3 | Audit logging of the two-factor authentication | TC-AF-1-03-027 |
| 3.3 | Rule: The 2FA requires a one-time code at login. | TC-AF-1-03-019 |
| 3.3 | Rule: Backup codes are provided for recovery. | TC-AF-1-03-020 |
| 3.3 | Rule: The 2FA can be disabled or reconfigured. | TC-AF-1-03-021 |
| 3.3 | Rule: 2FA events (enabled, disabled, code verified) are logged with the account and the timestamp. | TC-AF-1-03-022 |
| 3.3 | Rule: The two-factor authentication is audit-logged with the account and the timestamp. | TC-AF-1-03-023 |

## 3.1 Change Password

### TC-AF-1-03-001 — Enter the current password
**Type:** Positive
**Covers:** 3.1 → Enter the current password; Rule: The current password is required.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Enter the current password.
2. Observe the result and verify the full behavior: Enter the current password.
**Expected Result:** Enter the current password — delivered exactly as documented.
**Priority:** Critical

### TC-AF-1-03-002 — Enter a new password
**Type:** Positive
**Covers:** 3.1 → Enter a new password; Rule: The new password strength is validated.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Enter a new password.
2. Observe the result and verify the full behavior: Enter a new password.
**Expected Result:** Enter a new password — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-003 — New password strength validation
**Type:** Edge
**Covers:** 3.1 → New password strength validation; Rule: Other active sessions are signed out on change.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: New password strength validation.
2. Observe the result and verify the full behavior: New password strength validation.
**Expected Result:** New password strength validation — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-004 — Password updated on success
**Type:** Positive
**Covers:** 3.1 → Password updated on success; Rule: Change events (initiated, completed) are logged with the account and the timestamp.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Password updated on success.
2. Observe the result and verify the full behavior: Password updated on success.
**Expected Result:** Password updated on success — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-005 — Other active sessions signed out on change
**Type:** Positive
**Covers:** 3.1 → Other active sessions signed out on change; Rule: The change password is audit-logged with the account and the timestamp.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Other active sessions signed out on change.
2. Observe the result and verify the full behavior: Other active sessions signed out on change.
**Expected Result:** Other active sessions signed out on change — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-006 — Change confirmation
**Type:** Positive
**Covers:** 3.1 → Change confirmation
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Change confirmation.
2. Observe the result and verify the full behavior: Change confirmation.
**Expected Result:** Change confirmation — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-007 — Change available on web and mobile
**Type:** Positive
**Covers:** 3.1 → Change available on web and mobile
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Change available on web and mobile.
2. Observe the result and verify the full behavior: Change available on web and mobile.
**Expected Result:** Change available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-008 — Change event logging (initiated, completed)
**Type:** Positive
**Covers:** 3.1 → Change event logging (initiated, completed)
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Change event logging (initiated, completed).
2. Observe the result and verify the full behavior: Change event logging (initiated, completed).
**Expected Result:** Change event logging (initiated, completed) — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-009 — Audit logging of the change password
**Type:** Positive
**Covers:** 3.1 → Audit logging of the change password
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, perform the change password action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The change password action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical


## 3.2 Forgot Password

### TC-AF-1-03-010 — Enter the registered email to start a reset
**Type:** Positive
**Covers:** 3.2 → Enter the registered email to start a reset; Rule: The reset is started with the registered email.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Enter the registered email to start a reset.
2. Observe the result and verify the full behavior: Enter the registered email to start a reset.
**Expected Result:** Enter the registered email to start a reset — delivered exactly as documented.
**Priority:** Critical

### TC-AF-1-03-011 — Reset link sent to the email
**Type:** Positive
**Covers:** 3.2 → Reset link sent to the email; Rule: The reset link is single-use and expires.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Reset link sent to the email.
2. Observe the result and verify the full behavior: Reset link sent to the email.
**Expected Result:** Reset link sent to the email — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-012 — Set a new password via the link
**Type:** Positive
**Covers:** 3.2 → Set a new password via the link; Rule: A resend has a cooldown.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Set a new password via the link.
2. Observe the result and verify the full behavior: Set a new password via the link.
**Expected Result:** Set a new password via the link — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-013 — Reset link is single-use
**Type:** Edge
**Covers:** 3.2 → Reset link is single-use; Rule: Reset events (requested, completed) are logged with the account and the timestamp.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Reset link is single-use.
2. Observe the result and verify the full behavior: Reset link is single-use.
**Expected Result:** Reset link is single-use — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-014 — Reset link expires
**Type:** Edge
**Covers:** 3.2 → Reset link expires; Rule: The forgot password is audit-logged with the account and the timestamp.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Reset link expires.
2. Observe the result and verify the full behavior: Reset link expires.
**Expected Result:** Reset link expires — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-015 — Resend reset link with a cooldown
**Type:** Edge
**Covers:** 3.2 → Resend reset link with a cooldown
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Resend reset link with a cooldown.
2. Observe the result and verify the full behavior: Resend reset link with a cooldown.
**Expected Result:** Resend reset link with a cooldown — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-016 — Reset available on web and mobile
**Type:** Positive
**Covers:** 3.2 → Reset available on web and mobile
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Reset available on web and mobile.
2. Observe the result and verify the full behavior: Reset available on web and mobile.
**Expected Result:** Reset available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-017 — Reset event logging (requested, completed)
**Type:** Positive
**Covers:** 3.2 → Reset event logging (requested, completed)
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Reset event logging (requested, completed).
2. Observe the result and verify the full behavior: Reset event logging (requested, completed).
**Expected Result:** Reset event logging (requested, completed) — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-018 — Audit logging of the forgot password
**Type:** Positive
**Covers:** 3.2 → Audit logging of the forgot password
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, perform the forgot password action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The forgot password action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical


## 3.3 Two-Factor Authentication (2FA)

### TC-AF-1-03-019 — Enable two-factor authentication
**Type:** Positive
**Covers:** 3.3 → Enable two-factor authentication; Rule: The 2FA requires a one-time code at login.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Enable two-factor authentication.
2. Observe the result and verify the full behavior: Enable two-factor authentication.
**Expected Result:** Enable two-factor authentication — delivered exactly as documented.
**Priority:** Critical

### TC-AF-1-03-020 — One-time code at login (authenticator or SMS)
**Type:** Positive
**Covers:** 3.3 → One-time code at login (authenticator or SMS); Rule: Backup codes are provided for recovery.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: One-time code at login (authenticator or SMS).
2. Observe the result and verify the full behavior: One-time code at login (authenticator or SMS).
**Expected Result:** One-time code at login (authenticator or SMS) — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-021 — Backup codes for recovery
**Type:** Positive
**Covers:** 3.3 → Backup codes for recovery; Rule: The 2FA can be disabled or reconfigured.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Backup codes for recovery.
2. Observe the result and verify the full behavior: Backup codes for recovery.
**Expected Result:** Backup codes for recovery — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-022 — Disable two-factor authentication
**Type:** Positive
**Covers:** 3.3 → Disable two-factor authentication; Rule: 2FA events (enabled, disabled, code verified) are logged with the account and the timestamp.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Disable two-factor authentication.
2. Observe the result and verify the full behavior: Disable two-factor authentication.
**Expected Result:** Disable two-factor authentication — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-023 — Reconfigure the 2FA method
**Type:** Positive
**Covers:** 3.3 → Reconfigure the 2FA method; Rule: The two-factor authentication is audit-logged with the account and the timestamp.
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: Reconfigure the 2FA method.
2. Observe the result and verify the full behavior: Reconfigure the 2FA method.
**Expected Result:** Reconfigure the 2FA method — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-024 — 2FA status shown
**Type:** Positive
**Covers:** 3.3 → 2FA status shown
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: 2FA status shown.
2. Observe the result and verify the full behavior: 2FA status shown.
**Expected Result:** 2FA status shown — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-025 — 2FA available on web and mobile
**Type:** Positive
**Covers:** 3.3 → 2FA available on web and mobile
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: 2FA available on web and mobile.
2. Observe the result and verify the full behavior: 2FA available on web and mobile.
**Expected Result:** 2FA available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-026 — 2FA event logging (enabled, disabled, code verified)
**Type:** Positive
**Covers:** 3.3 → 2FA event logging (enabled, disabled, code verified)
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, set up the precondition and perform: 2FA event logging (enabled, disabled, code verified).
2. Observe the result and verify the full behavior: 2FA event logging (enabled, disabled, code verified).
**Expected Result:** 2FA event logging (enabled, disabled, code verified) — delivered exactly as documented.
**Priority:** High

### TC-AF-1-03-027 — Audit logging of the two-factor authentication
**Type:** Positive
**Covers:** 3.3 → Audit logging of the two-factor authentication
**Preconditions:** A Affiliate account is active and the Affiliate is in the state required for this behavior.
**Steps:**
1. As a Affiliate, perform the two-factor authentication action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The two-factor authentication action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical
