# 1. Login & Security — Test Cases

User Type: **Organization**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: login_security.md — every feature, sub-feature, and rule covered

## Test Execution Policy

- Zero tolerance: any deviation from the documented behavior is a defect.
- Every failed test is logged with a Bug ID, the feature, the sub-feature, the expected vs actual result, and the severity; 100% of bugs are fixed before the group passes.
- 100% pass rate is required for the group to be marked complete.

## Coverage Matrix

| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 1.1 | Email + password login | TC-ORG-1-01-001 |
| 1.1 | OTP verification on login | TC-ORG-1-01-002 |
| 1.1 | Two-factor authentication (2FA) | TC-ORG-1-01-003 |
| 1.1 | Password reset via email link | TC-ORG-1-01-004 |
| 1.1 | Session timeout and auto-logout | TC-ORG-1-01-005 |
| 1.1 | Secure Login available on web and mobile | TC-ORG-1-01-006 |
| 1.1 | secure login event logging (viewed) | TC-ORG-1-01-007 |
| 1.1 | Audit logging of secure login | TC-ORG-1-01-008 |
| 1.1 | Rule: Email + password login. | TC-ORG-1-01-009 |
| 1.1 | Rule: OTP verification on login. | TC-ORG-1-01-010 |
| 1.1 | Rule: Two-factor authentication (2FA). | TC-ORG-1-01-011 |
| 1.1 | Rule: Password reset via email link. | TC-ORG-1-01-012 |
| 1.1 | Rule: Session timeout and auto-logout. | TC-ORG-1-01-013 |
| 1.2 | Organization registration form (name, type, registration details) | TC-ORG-1-02-014 |
| 1.2 | Organization type: NGO, government body, educational board | TC-ORG-1-02-015 |
| 1.2 | Primary admin setup with verification | TC-ORG-1-02-016 |
| 1.2 | Additional admin invitations with roles | TC-ORG-1-02-017 |
| 1.2 | Account status: pending, verified, suspended | TC-ORG-1-02-018 |
| 1.2 | Registration & Multi-Admin Setup available on web and mobile | TC-ORG-1-02-019 |
| 1.2 | registration & multi-admin setup event logging (viewed) | TC-ORG-1-02-020 |
| 1.2 | Audit logging of registration & multi-admin setup | TC-ORG-1-02-021 |
| 1.2 | Rule: Organization registration form (name, type, registration details). | TC-ORG-1-02-022 |
| 1.2 | Rule: Organization type: NGO, government body, educational board. | TC-ORG-1-02-023 |
| 1.2 | Rule: Primary admin setup with verification. | TC-ORG-1-02-024 |
| 1.2 | Rule: Additional admin invitations with roles. | TC-ORG-1-02-025 |
| 1.2 | Rule: Account status: pending, verified, suspended. | TC-ORG-1-02-026 |

## 1.1 Secure Login

### TC-ORG-1-01-001 — Email + password login
**Type:** Positive
**Covers:** 1.1 → Email + password login; Rule: Email + password login.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Email + password login.
2. Observe the result and verify the full behavior: Email + password login.
**Expected Result:** Email + password login — delivered exactly as documented.
**Priority:** Critical

### TC-ORG-1-01-002 — OTP verification on login
**Type:** Positive
**Covers:** 1.1 → OTP verification on login; Rule: OTP verification on login.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: OTP verification on login.
2. Observe the result and verify the full behavior: OTP verification on login.
**Expected Result:** OTP verification on login — delivered exactly as documented.
**Priority:** High

### TC-ORG-1-01-003 — Two-factor authentication (2FA)
**Type:** Positive
**Covers:** 1.1 → Two-factor authentication (2FA); Rule: Two-factor authentication (2FA).
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Two-factor authentication (2FA).
2. Observe the result and verify the full behavior: Two-factor authentication (2FA).
**Expected Result:** Two-factor authentication (2FA) — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-01-004 — Password reset via email link
**Type:** Positive
**Covers:** 1.1 → Password reset via email link; Rule: Password reset via email link.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Password reset via email link.
2. Observe the result and verify the full behavior: Password reset via email link.
**Expected Result:** Password reset via email link — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-01-005 — Session timeout and auto-logout
**Type:** Positive
**Covers:** 1.1 → Session timeout and auto-logout; Rule: Session timeout and auto-logout.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Session timeout and auto-logout.
2. Observe the result and verify the full behavior: Session timeout and auto-logout.
**Expected Result:** Session timeout and auto-logout — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-01-006 — Secure Login available on web and mobile
**Type:** Positive
**Covers:** 1.1 → Secure Login available on web and mobile; Rule: Email + password login.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Secure Login available on web and mobile.
2. Observe the result and verify the full behavior: Secure Login available on web and mobile.
**Expected Result:** Secure Login available on web and mobile — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-01-007 — secure login event logging (viewed)
**Type:** Positive
**Covers:** 1.1 → secure login event logging (viewed); Rule: OTP verification on login.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: secure login event logging (viewed).
2. Observe the result and verify the full behavior: secure login event logging (viewed).
**Expected Result:** secure login event logging (viewed) — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-01-008 — Audit logging of secure login
**Type:** Positive
**Covers:** 1.1 → Audit logging of secure login; Rule: Two-factor authentication (2FA).
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Audit logging of secure login.
2. Observe the result and verify the full behavior: Audit logging of secure login.
**Expected Result:** Audit logging of secure login — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-01-009 — Rule: Email + password login.
**Type:** Positive
**Covers:** 1.1 → Rule: Email + password login.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: Email + password login.
2. Observe the result and verify the full behavior: Email + password login.
**Expected Result:** Email + password login. — delivered exactly as documented.
**Priority:** Critical

### TC-ORG-1-01-010 — Rule: OTP verification on login.
**Type:** Positive
**Covers:** 1.1 → Rule: OTP verification on login.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: OTP verification on login.
2. Observe the result and verify the full behavior: OTP verification on login.
**Expected Result:** OTP verification on login. — delivered exactly as documented.
**Priority:** High

### TC-ORG-1-01-011 — Rule: Two-factor authentication (2FA).
**Type:** Positive
**Covers:** 1.1 → Rule: Two-factor authentication (2FA).
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: Two-factor authentication (2FA).
2. Observe the result and verify the full behavior: Two-factor authentication (2FA).
**Expected Result:** Two-factor authentication (2FA). — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-01-012 — Rule: Password reset via email link.
**Type:** Positive
**Covers:** 1.1 → Rule: Password reset via email link.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: Password reset via email link.
2. Observe the result and verify the full behavior: Password reset via email link.
**Expected Result:** Password reset via email link. — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-01-013 — Rule: Session timeout and auto-logout.
**Type:** Positive
**Covers:** 1.1 → Rule: Session timeout and auto-logout.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: Session timeout and auto-logout.
2. Observe the result and verify the full behavior: Session timeout and auto-logout.
**Expected Result:** Session timeout and auto-logout. — delivered exactly as documented.
**Priority:** Medium

## 1.2 Registration & Multi-Admin Setup

### TC-ORG-1-02-014 — Organization registration form (name, type, registration details)
**Type:** Positive
**Covers:** 1.2 → Organization registration form (name, type, registration details); Rule: Organization registration form (name, type, registration details).
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Organization registration form (name, type, registration details).
2. Observe the result and verify the full behavior: Organization registration form (name, type, registration details).
**Expected Result:** Organization registration form (name, type, registration details) — delivered exactly as documented.
**Priority:** Critical

### TC-ORG-1-02-015 — Organization type: NGO, government body, educational board
**Type:** Positive
**Covers:** 1.2 → Organization type: NGO, government body, educational board; Rule: Organization type: NGO, government body, educational board.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Organization type: NGO, government body, educational board.
2. Observe the result and verify the full behavior: Organization type: NGO, government body, educational board.
**Expected Result:** Organization type: NGO, government body, educational board — delivered exactly as documented.
**Priority:** High

### TC-ORG-1-02-016 — Primary admin setup with verification
**Type:** Positive
**Covers:** 1.2 → Primary admin setup with verification; Rule: Primary admin setup with verification.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Primary admin setup with verification.
2. Observe the result and verify the full behavior: Primary admin setup with verification.
**Expected Result:** Primary admin setup with verification — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-02-017 — Additional admin invitations with roles
**Type:** Positive
**Covers:** 1.2 → Additional admin invitations with roles; Rule: Additional admin invitations with roles.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Additional admin invitations with roles.
2. Observe the result and verify the full behavior: Additional admin invitations with roles.
**Expected Result:** Additional admin invitations with roles — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-02-018 — Account status: pending, verified, suspended
**Type:** Positive
**Covers:** 1.2 → Account status: pending, verified, suspended; Rule: Account status: pending, verified, suspended.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Account status: pending, verified, suspended.
2. Observe the result and verify the full behavior: Account status: pending, verified, suspended.
**Expected Result:** Account status: pending, verified, suspended — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-02-019 — Registration & Multi-Admin Setup available on web and mobile
**Type:** Positive
**Covers:** 1.2 → Registration & Multi-Admin Setup available on web and mobile; Rule: Organization registration form (name, type, registration details).
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Registration & Multi-Admin Setup available on web and mobile.
2. Observe the result and verify the full behavior: Registration & Multi-Admin Setup available on web and mobile.
**Expected Result:** Registration & Multi-Admin Setup available on web and mobile — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-02-020 — registration & multi-admin setup event logging (viewed)
**Type:** Positive
**Covers:** 1.2 → registration & multi-admin setup event logging (viewed); Rule: Organization type: NGO, government body, educational board.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: registration & multi-admin setup event logging (viewed).
2. Observe the result and verify the full behavior: registration & multi-admin setup event logging (viewed).
**Expected Result:** registration & multi-admin setup event logging (viewed) — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-02-021 — Audit logging of registration & multi-admin setup
**Type:** Positive
**Covers:** 1.2 → Audit logging of registration & multi-admin setup; Rule: Primary admin setup with verification.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform: Audit logging of registration & multi-admin setup.
2. Observe the result and verify the full behavior: Audit logging of registration & multi-admin setup.
**Expected Result:** Audit logging of registration & multi-admin setup — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-02-022 — Rule: Organization registration form (name, type, registration details).
**Type:** Positive
**Covers:** 1.2 → Rule: Organization registration form (name, type, registration details).
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: Organization registration form (name, type, registration details).
2. Observe the result and verify the full behavior: Organization registration form (name, type, registration details).
**Expected Result:** Organization registration form (name, type, registration details). — delivered exactly as documented.
**Priority:** Critical

### TC-ORG-1-02-023 — Rule: Organization type: NGO, government body, educational board.
**Type:** Positive
**Covers:** 1.2 → Rule: Organization type: NGO, government body, educational board.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: Organization type: NGO, government body, educational board.
2. Observe the result and verify the full behavior: Organization type: NGO, government body, educational board.
**Expected Result:** Organization type: NGO, government body, educational board. — delivered exactly as documented.
**Priority:** High

### TC-ORG-1-02-024 — Rule: Primary admin setup with verification.
**Type:** Positive
**Covers:** 1.2 → Rule: Primary admin setup with verification.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: Primary admin setup with verification.
2. Observe the result and verify the full behavior: Primary admin setup with verification.
**Expected Result:** Primary admin setup with verification. — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-02-025 — Rule: Additional admin invitations with roles.
**Type:** Positive
**Covers:** 1.2 → Rule: Additional admin invitations with roles.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: Additional admin invitations with roles.
2. Observe the result and verify the full behavior: Additional admin invitations with roles.
**Expected Result:** Additional admin invitations with roles. — delivered exactly as documented.
**Priority:** Medium

### TC-ORG-1-02-026 — Rule: Account status: pending, verified, suspended.
**Type:** Positive
**Covers:** 1.2 → Rule: Account status: pending, verified, suspended.
**Preconditions:** A Organization account is active and the Organization is in the state required for this behavior.
**Steps:**
1. As a Organization, set up the precondition and perform the action that triggers the rule: Account status: pending, verified, suspended.
2. Observe the result and verify the full behavior: Account status: pending, verified, suspended.
**Expected Result:** Account status: pending, verified, suspended. — delivered exactly as documented.
**Priority:** Medium
