# 3. Password Management — Test Cases

User Type: **Parent**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: password_management.md — every feature, sub-feature, and rule covered

---

## Test Execution Policy
- Zero tolerance: any deviation from documented behavior = FAILED = bug
- Every bug is immediately logged/reported (Bug ID, feature, sub-feature, expected vs actual, severity) and fixed 100% before the group passes
- Feature group passes only at 100% test pass rate

## Coverage Matrix
| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 3.1 Change Password | Change the account password | TC-PT-1-03-001 |
| 3.1 Change Password | Verify the current password | TC-PT-1-03-002 |
| 3.1 Change Password | New password strength requirements | TC-PT-1-03-003 |
| 3.1 Change Password | Confirm the new password | TC-PT-1-03-004 |
| 3.1 Change Password | Password change confirmation | TC-PT-1-03-005 |
| 3.1 Change Password | Other sessions signed out on change | TC-PT-1-03-006 |
| 3.1 Change Password | Password change event logging (changed) | TC-PT-1-03-007 |
| 3.1 Change Password | Audit logging of the change password | TC-PT-1-03-008 |
| 3.1 Change Password | Rule: The current password must be verified. | TC-PT-1-03-001 |
| 3.1 Change Password | Rule: The new password must meet the strength requirements. | TC-PT-1-03-002 |
| 3.1 Change Password | Rule: The new password must be confirmed. | TC-PT-1-03-003 |
| 3.1 Change Password | Rule: Other sessions are signed out on a password change. | TC-PT-1-03-004 |
| 3.1 Change Password | Rule: Password change events (changed) are logged with the account and the timestamp. | TC-PT-1-03-005 |
| 3.1 Change Password | Rule: The change password is audit-logged with the account and the timestamp. | TC-PT-1-03-006 |
| 3.2 Forgot Password | Request a password reset by email | TC-PT-1-03-009 |
| 3.2 Forgot Password | Password reset link sent to the email | TC-PT-1-03-010 |
| 3.2 Forgot Password | Reset link expiry | TC-PT-1-03-011 |
| 3.2 Forgot Password | Set a new password from the link | TC-PT-1-03-012 |
| 3.2 Forgot Password | New password strength requirements | TC-PT-1-03-013 |
| 3.2 Forgot Password | Reset link single-use | TC-PT-1-03-014 |
| 3.2 Forgot Password | Reset event logging (requested, link used, password reset) | TC-PT-1-03-015 |
| 3.2 Forgot Password | Audit logging of the forgot password | TC-PT-1-03-016 |
| 3.2 Forgot Password | Rule: The reset link is sent to the registered email. | TC-PT-1-03-009 |
| 3.2 Forgot Password | Rule: The reset link expires after the platform's window. | TC-PT-1-03-010 |
| 3.2 Forgot Password | Rule: The reset link is single-use. | TC-PT-1-03-011 |
| 3.2 Forgot Password | Rule: The new password must meet the strength requirements. | TC-PT-1-03-012 |
| 3.2 Forgot Password | Rule: Reset events (requested, link used, password reset) are logged with the account and the timestamp. | TC-PT-1-03-013 |
| 3.2 Forgot Password | Rule: The forgot password is audit-logged with the account and the timestamp. | TC-PT-1-03-014 |
| 3.3 Two-Factor Authentication (2FA) | Enable two-factor authentication | TC-PT-1-03-017 |
| 3.3 Two-Factor Authentication (2FA) | 2FA code at login (authenticator app or SMS) | TC-PT-1-03-018 |
| 3.3 Two-Factor Authentication (2FA) | Backup codes for recovery | TC-PT-1-03-019 |
| 3.3 Two-Factor Authentication (2FA) | Disable two-factor authentication | TC-PT-1-03-020 |
| 3.3 Two-Factor Authentication (2FA) | 2FA status shown on the account | TC-PT-1-03-021 |
| 3.3 Two-Factor Authentication (2FA) | 2FA event logging (enabled, code verified, disabled) | TC-PT-1-03-022 |
| 3.3 Two-Factor Authentication (2FA) | Audit logging of the two-factor authentication | TC-PT-1-03-023 |
| 3.3 Two-Factor Authentication (2FA) | Rule: 2FA requires an authenticator app or SMS. | TC-PT-1-03-017 |
| 3.3 Two-Factor Authentication (2FA) | Rule: A 2FA code is required at login when enabled. | TC-PT-1-03-018 |
| 3.3 Two-Factor Authentication (2FA) | Rule: Backup codes can be used for recovery. | TC-PT-1-03-019 |
| 3.3 Two-Factor Authentication (2FA) | Rule: 2FA can be disabled by the Parent. | TC-PT-1-03-020 |
| 3.3 Two-Factor Authentication (2FA) | Rule: 2FA events (enabled, code verified, disabled) are logged with the account and the timestamp. | TC-PT-1-03-021 |
| 3.3 Two-Factor Authentication (2FA) | Rule: The two-factor authentication is audit-logged with the account and the timestamp. | TC-PT-1-03-022 |

## 3.1 Change Password

### TC-PT-1-03-001 — Change the account password
**Type:** Positive
**Covers:** 3.1 → Change the account password; Rule: The current password must be verified.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Change the account password.
2. Observe the result and verify the full behavior: Change the account password.
**Expected Result:** Change the account password — delivered exactly as documented.
**Priority:** Critical

### TC-PT-1-03-002 — Verify the current password
**Type:** Positive
**Covers:** 3.1 → Verify the current password; Rule: The new password must meet the strength requirements.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Verify the current password.
2. Observe the result and verify the full behavior: Verify the current password.
**Expected Result:** Verify the current password — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-003 — New password strength requirements
**Type:** Edge
**Covers:** 3.1 → New password strength requirements; Rule: The new password must be confirmed.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: New password strength requirements.
2. Observe the result and verify the full behavior: New password strength requirements.
**Expected Result:** New password strength requirements — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-004 — Confirm the new password
**Type:** Positive
**Covers:** 3.1 → Confirm the new password; Rule: Other sessions are signed out on a password change.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Confirm the new password.
2. Observe the result and verify the full behavior: Confirm the new password.
**Expected Result:** Confirm the new password — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-005 — Password change confirmation
**Type:** Positive
**Covers:** 3.1 → Password change confirmation; Rule: Password change events (changed) are logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Password change confirmation.
2. Observe the result and verify the full behavior: Password change confirmation.
**Expected Result:** Password change confirmation — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-006 — Other sessions signed out on change
**Type:** Positive
**Covers:** 3.1 → Other sessions signed out on change; Rule: The change password is audit-logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Other sessions signed out on change.
2. Observe the result and verify the full behavior: Other sessions signed out on change.
**Expected Result:** Other sessions signed out on change — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-007 — Password change event logging (changed)
**Type:** Positive
**Covers:** 3.1 → Password change event logging (changed)
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Password change event logging (changed).
2. Observe the result and verify the full behavior: Password change event logging (changed).
**Expected Result:** Password change event logging (changed) — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-008 — Audit logging of the change password
**Type:** Positive
**Covers:** 3.1 → Audit logging of the change password
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, perform the action associated with: Audit logging of the change password.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical

## 3.2 Forgot Password

### TC-PT-1-03-009 — Request a password reset by email
**Type:** Positive
**Covers:** 3.2 → Request a password reset by email; Rule: The reset link is sent to the registered email.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Request a password reset by email.
2. Observe the result and verify the full behavior: Request a password reset by email.
**Expected Result:** Request a password reset by email — delivered exactly as documented.
**Priority:** Critical

### TC-PT-1-03-010 — Password reset link sent to the email
**Type:** Positive
**Covers:** 3.2 → Password reset link sent to the email; Rule: The reset link expires after the platform's window.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Password reset link sent to the email.
2. Observe the result and verify the full behavior: Password reset link sent to the email.
**Expected Result:** Password reset link sent to the email — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-011 — Reset link expiry
**Type:** Edge
**Covers:** 3.2 → Reset link expiry; Rule: The reset link is single-use.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Reset link expiry.
2. Observe the result and verify the full behavior: Reset link expiry.
**Expected Result:** Reset link expiry — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-012 — Set a new password from the link
**Type:** Positive
**Covers:** 3.2 → Set a new password from the link; Rule: The new password must meet the strength requirements.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Set a new password from the link.
2. Observe the result and verify the full behavior: Set a new password from the link.
**Expected Result:** Set a new password from the link — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-013 — New password strength requirements
**Type:** Edge
**Covers:** 3.2 → New password strength requirements; Rule: Reset events (requested, link used, password reset) are logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: New password strength requirements.
2. Observe the result and verify the full behavior: New password strength requirements.
**Expected Result:** New password strength requirements — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-014 — Reset link single-use
**Type:** Edge
**Covers:** 3.2 → Reset link single-use; Rule: The forgot password is audit-logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Reset link single-use.
2. Observe the result and verify the full behavior: Reset link single-use.
**Expected Result:** Reset link single-use — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-015 — Reset event logging (requested, link used, password reset)
**Type:** Positive
**Covers:** 3.2 → Reset event logging (requested, link used, password reset)
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Reset event logging (requested.
2. Observe the result and verify the full behavior: Reset event logging (requested, link used, password reset).
**Expected Result:** Reset event logging (requested, link used, password reset) — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-016 — Audit logging of the forgot password
**Type:** Positive
**Covers:** 3.2 → Audit logging of the forgot password
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, perform the action associated with: Audit logging of the forgot password.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical

## 3.3 Two-Factor Authentication (2FA)

### TC-PT-1-03-017 — Enable two-factor authentication
**Type:** Positive
**Covers:** 3.3 → Enable two-factor authentication; Rule: 2FA requires an authenticator app or SMS.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Enable two-factor authentication.
2. Observe the result and verify the full behavior: Enable two-factor authentication.
**Expected Result:** Enable two-factor authentication — delivered exactly as documented.
**Priority:** Critical

### TC-PT-1-03-018 — 2FA code at login (authenticator app or SMS)
**Type:** Positive
**Covers:** 3.3 → 2FA code at login (authenticator app or SMS); Rule: A 2FA code is required at login when enabled.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: 2FA code at login (authenticator app or SMS).
2. Observe the result and verify the full behavior: 2FA code at login (authenticator app or SMS).
**Expected Result:** 2FA code at login (authenticator app or SMS) — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-019 — Backup codes for recovery
**Type:** Positive
**Covers:** 3.3 → Backup codes for recovery; Rule: Backup codes can be used for recovery.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Backup codes for recovery.
2. Observe the result and verify the full behavior: Backup codes for recovery.
**Expected Result:** Backup codes for recovery — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-020 — Disable two-factor authentication
**Type:** Positive
**Covers:** 3.3 → Disable two-factor authentication; Rule: 2FA can be disabled by the Parent.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Disable two-factor authentication.
2. Observe the result and verify the full behavior: Disable two-factor authentication.
**Expected Result:** Disable two-factor authentication — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-021 — 2FA status shown on the account
**Type:** Positive
**Covers:** 3.3 → 2FA status shown on the account; Rule: 2FA events (enabled, code verified, disabled) are logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: 2FA status shown on the account.
2. Observe the result and verify the full behavior: 2FA status shown on the account.
**Expected Result:** 2FA status shown on the account — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-022 — 2FA event logging (enabled, code verified, disabled)
**Type:** Positive
**Covers:** 3.3 → 2FA event logging (enabled, code verified, disabled); Rule: The two-factor authentication is audit-logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: 2FA event logging (enabled.
2. Observe the result and verify the full behavior: 2FA event logging (enabled, code verified, disabled).
**Expected Result:** 2FA event logging (enabled, code verified, disabled) — delivered exactly as documented.
**Priority:** High

### TC-PT-1-03-023 — Audit logging of the two-factor authentication
**Type:** Positive
**Covers:** 3.3 → Audit logging of the two-factor authentication
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, perform the action associated with: Audit logging of the two-factor authentication.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical
