# 3. Institute Security & Password Management — Test Cases

User Type: **Training Institute**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: institute_security_password.md — every feature, sub-feature, and rule covered

## Test Execution Policy

- Zero tolerance: any deviation from the documented behavior is a defect.
- Every failed test is logged with a Bug ID, the feature, the sub-feature, the expected vs actual result, and the severity; 100% of bugs are fixed before the group passes.
- 100% pass rate is required for the group to be marked complete.

## Coverage Matrix

| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 3.1 | Change password form | TC-TI-1-03-001 |
| 3.1 | Current password required | TC-TI-1-03-002 |
| 3.1 | New password strength requirements | TC-TI-1-03-003 |
| 3.1 | Password updated on save | TC-TI-1-03-004 |
| 3.1 | Other sessions optionally signed out | TC-TI-1-03-005 |
| 3.1 | Change available on web and mobile | TC-TI-1-03-006 |
| 3.1 | Change event logging (password changed) | TC-TI-1-03-007 |
| 3.1 | Audit logging of the change password | TC-TI-1-03-008 |
| 3.1 | Rule: The current password is required. | TC-TI-1-03-001 |
| 3.1 | Rule: The new password must meet the strength requirements. | TC-TI-1-03-002 |
| 3.1 | Rule: Change events (password changed) are logged with the account and the timestamp. | TC-TI-1-03-003 |
| 3.1 | Rule: The change password is audit-logged with the account and the timestamp. | TC-TI-1-03-004 |
| 3.2 | Forgot password form | TC-TI-1-03-009 |
| 3.2 | Reset link sent to the registered email | TC-TI-1-03-010 |
| 3.2 | New password set via the link | TC-TI-1-03-011 |
| 3.2 | Reset link single-use | TC-TI-1-03-012 |
| 3.2 | Reset link time-limited | TC-TI-1-03-013 |
| 3.2 | Reset available on web and mobile | TC-TI-1-03-014 |
| 3.2 | Reset event logging (link sent, password reset) | TC-TI-1-03-015 |
| 3.2 | Audit logging of the forgot password | TC-TI-1-03-016 |
| 3.2 | Rule: The reset link is single-use. | TC-TI-1-03-009 |
| 3.2 | Rule: The reset link is time-limited. | TC-TI-1-03-010 |
| 3.2 | Rule: Reset events (link sent, password reset) are logged with the account and the timestamp. | TC-TI-1-03-011 |
| 3.2 | Rule: The forgot password is audit-logged with the account and the timestamp. | TC-TI-1-03-012 |
| 3.3 | Active sessions list | TC-TI-1-03-017 |
| 3.3 | Device, location, and last activity per session | TC-TI-1-03-018 |
| 3.3 | Sign out a specific session | TC-TI-1-03-019 |
| 3.3 | Sign out all other sessions | TC-TI-1-03-020 |
| 3.3 | Current session marked | TC-TI-1-03-021 |
| 3.3 | Sessions available on web and mobile | TC-TI-1-03-022 |
| 3.3 | Sessions event logging (signed out) | TC-TI-1-03-023 |
| 3.3 | Audit logging of the active sessions and sign out | TC-TI-1-03-024 |
| 3.3 | Rule: The current session cannot be signed out from the list. | TC-TI-1-03-017 |
| 3.3 | Rule: A signed-out session is terminated immediately. | TC-TI-1-03-018 |
| 3.3 | Rule: Sessions events (signed out) are logged with the account and the timestamp. | TC-TI-1-03-019 |
| 3.3 | Rule: The active sessions and sign out is audit-logged with the account and the timestamp. | TC-TI-1-03-020 |

## 3.1 Change Password

### TC-TI-1-03-001 — Change password form
**Type:** Positive
**Covers:** 3.1 → Change password form; Rule: The current password is required.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Change password form.
2. Observe the result and verify the full behavior: Change password form.
**Expected Result:** Change password form — delivered exactly as documented.
**Priority:** Critical

### TC-TI-1-03-002 — Current password required
**Type:** Edge
**Covers:** 3.1 → Current password required; Rule: The new password must meet the strength requirements.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Current password required.
2. Observe the result and verify the full behavior: Current password required.
**Expected Result:** Current password required — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-003 — New password strength requirements
**Type:** Edge
**Covers:** 3.1 → New password strength requirements; Rule: Change events (password changed) are logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: New password strength requirements.
2. Observe the result and verify the full behavior: New password strength requirements.
**Expected Result:** New password strength requirements — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-004 — Password updated on save
**Type:** Positive
**Covers:** 3.1 → Password updated on save; Rule: The change password is audit-logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Password updated on save.
2. Observe the result and verify the full behavior: Password updated on save.
**Expected Result:** Password updated on save — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-005 — Other sessions optionally signed out
**Type:** Positive
**Covers:** 3.1 → Other sessions optionally signed out
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Other sessions optionally signed out.
2. Observe the result and verify the full behavior: Other sessions optionally signed out.
**Expected Result:** Other sessions optionally signed out — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-006 — Change available on web and mobile
**Type:** Positive
**Covers:** 3.1 → Change available on web and mobile
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Change available on web and mobile.
2. Observe the result and verify the full behavior: Change available on web and mobile.
**Expected Result:** Change available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-007 — Change event logging (password changed)
**Type:** Positive
**Covers:** 3.1 → Change event logging (password changed)
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Change event logging (password changed).
2. Observe the result and verify the full behavior: Change event logging (password changed).
**Expected Result:** Change event logging (password changed) — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-008 — Audit logging of the change password
**Type:** Positive
**Covers:** 3.1 → Audit logging of the change password
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, perform the change password action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The change password action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical


## 3.2 Forgot Password

### TC-TI-1-03-009 — Forgot password form
**Type:** Positive
**Covers:** 3.2 → Forgot password form; Rule: The reset link is single-use.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Forgot password form.
2. Observe the result and verify the full behavior: Forgot password form.
**Expected Result:** Forgot password form — delivered exactly as documented.
**Priority:** Critical

### TC-TI-1-03-010 — Reset link sent to the registered email
**Type:** Positive
**Covers:** 3.2 → Reset link sent to the registered email; Rule: The reset link is time-limited.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Reset link sent to the registered email.
2. Observe the result and verify the full behavior: Reset link sent to the registered email.
**Expected Result:** Reset link sent to the registered email — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-011 — New password set via the link
**Type:** Positive
**Covers:** 3.2 → New password set via the link; Rule: Reset events (link sent, password reset) are logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: New password set via the link.
2. Observe the result and verify the full behavior: New password set via the link.
**Expected Result:** New password set via the link — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-012 — Reset link single-use
**Type:** Edge
**Covers:** 3.2 → Reset link single-use; Rule: The forgot password is audit-logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Reset link single-use.
2. Observe the result and verify the full behavior: Reset link single-use.
**Expected Result:** Reset link single-use — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-013 — Reset link time-limited
**Type:** Edge
**Covers:** 3.2 → Reset link time-limited
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Reset link time-limited.
2. Observe the result and verify the full behavior: Reset link time-limited.
**Expected Result:** Reset link time-limited — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-014 — Reset available on web and mobile
**Type:** Positive
**Covers:** 3.2 → Reset available on web and mobile
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Reset available on web and mobile.
2. Observe the result and verify the full behavior: Reset available on web and mobile.
**Expected Result:** Reset available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-015 — Reset event logging (link sent, password reset)
**Type:** Positive
**Covers:** 3.2 → Reset event logging (link sent, password reset)
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Reset event logging (link sent, password reset).
2. Observe the result and verify the full behavior: Reset event logging (link sent, password reset).
**Expected Result:** Reset event logging (link sent, password reset) — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-016 — Audit logging of the forgot password
**Type:** Positive
**Covers:** 3.2 → Audit logging of the forgot password
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, perform the forgot password action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The forgot password action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical


## 3.3 Active Sessions & Sign Out

### TC-TI-1-03-017 — Active sessions list
**Type:** Positive
**Covers:** 3.3 → Active sessions list; Rule: The current session cannot be signed out from the list.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Active sessions list.
2. Observe the result and verify the full behavior: Active sessions list.
**Expected Result:** Active sessions list — delivered exactly as documented.
**Priority:** Critical

### TC-TI-1-03-018 — Device, location, and last activity per session
**Type:** Positive
**Covers:** 3.3 → Device, location, and last activity per session; Rule: A signed-out session is terminated immediately.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Device, location, and last activity per session.
2. Observe the result and verify the full behavior: Device, location, and last activity per session.
**Expected Result:** Device, location, and last activity per session — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-019 — Sign out a specific session
**Type:** Positive
**Covers:** 3.3 → Sign out a specific session; Rule: Sessions events (signed out) are logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Sign out a specific session.
2. Observe the result and verify the full behavior: Sign out a specific session.
**Expected Result:** Sign out a specific session — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-020 — Sign out all other sessions
**Type:** Positive
**Covers:** 3.3 → Sign out all other sessions; Rule: The active sessions and sign out is audit-logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Sign out all other sessions.
2. Observe the result and verify the full behavior: Sign out all other sessions.
**Expected Result:** Sign out all other sessions — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-021 — Current session marked
**Type:** Positive
**Covers:** 3.3 → Current session marked
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Current session marked.
2. Observe the result and verify the full behavior: Current session marked.
**Expected Result:** Current session marked — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-022 — Sessions available on web and mobile
**Type:** Positive
**Covers:** 3.3 → Sessions available on web and mobile
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Sessions available on web and mobile.
2. Observe the result and verify the full behavior: Sessions available on web and mobile.
**Expected Result:** Sessions available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-023 — Sessions event logging (signed out)
**Type:** Positive
**Covers:** 3.3 → Sessions event logging (signed out)
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Sessions event logging (signed out).
2. Observe the result and verify the full behavior: Sessions event logging (signed out).
**Expected Result:** Sessions event logging (signed out) — delivered exactly as documented.
**Priority:** High

### TC-TI-1-03-024 — Audit logging of the active sessions and sign out
**Type:** Positive
**Covers:** 3.3 → Audit logging of the active sessions and sign out
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, perform the active sessions and sign out action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The active sessions and sign out action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical
