# 4. App Management & Security — Test Cases

User Type: **Student**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: app_management_security.md — every feature, sub-feature, and rule covered

---

## Test Execution Policy
- Zero tolerance: any deviation from documented behavior = FAILED = bug
- Every bug is immediately logged/reported (Bug ID, feature, sub-feature, expected vs actual, severity) and fixed 100% before the group passes
- Feature group passes only at 100% test pass rate

## Coverage Matrix
| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 4.1 App Availability and Updates | Mobile app on iOS and Android | TC-ST-13-04-001 |
| 4.1 App Availability and Updates | App updates through the app stores | TC-ST-13-04-002 |
| 4.1 App Availability and Updates | New version notification | TC-ST-13-04-003 |
| 4.1 App Availability and Updates | Minimum OS version support | TC-ST-13-04-004 |
| 4.1 App Availability and Updates | Update guidance for the OS | TC-ST-13-04-005 |
| 4.1 App Availability and Updates | App version shown in the app | TC-ST-13-04-006 |
| 4.1 App Availability and Updates | Update event logging (notified, updated) | TC-ST-13-04-007 |
| 4.1 App Availability and Updates | Audit logging of the app availability and updates | TC-ST-13-04-008 |
| 4.1 App Availability and Updates | Rule: The app is available on iOS and Android. | TC-ST-13-04-001 |
| 4.1 App Availability and Updates | Rule: Updates are delivered through the app stores. | TC-ST-13-04-002 |
| 4.1 App Availability and Updates | Rule: A new version notification is shown. | TC-ST-13-04-003 |
| 4.1 App Availability and Updates | Rule: The app supports the platform's minimum OS versions. | TC-ST-13-04-004 |
| 4.1 App Availability and Updates | Rule: Update events (notified, updated) are logged with the account and the timestamp. | TC-ST-13-04-005 |
| 4.1 App Availability and Updates | Rule: The app availability and updates is audit-logged with the account and the timestamp. | TC-ST-13-04-006 |
| 4.2 Push Notifications | Push notifications on the device | TC-ST-13-04-009 |
| 4.2 Push Notifications | Study reminder push notifications | TC-ST-13-04-010 |
| 4.2 Push Notifications | Session alert push notifications | TC-ST-13-04-011 |
| 4.2 Push Notifications | Achievement push notifications | TC-ST-13-04-012 |
| 4.2 Push Notifications | Report-ready push notifications | TC-ST-13-04-013 |
| 4.2 Push Notifications | Enable/disable push notifications | TC-ST-13-04-014 |
| 4.2 Push Notifications | Customize notification categories | TC-ST-13-04-015 |
| 4.2 Push Notifications | Push event logging (sent, opened, disabled) | TC-ST-13-04-016 |
| 4.2 Push Notifications | Audit logging of the push notifications | TC-ST-13-04-017 |
| 4.2 Push Notifications | Rule: Push notifications require the device permission. | TC-ST-13-04-009 |
| 4.2 Push Notifications | Rule: The Student can enable/disable push notifications. | TC-ST-13-04-010 |
| 4.2 Push Notifications | Rule: Notification categories can be customized. | TC-ST-13-04-011 |
| 4.2 Push Notifications | Rule: Push events (sent, opened, disabled) are logged with the account and the timestamp. | TC-ST-13-04-012 |
| 4.2 Push Notifications | Rule: The push notifications is audit-logged with the account and the timestamp. | TC-ST-13-04-013 |
| 4.3 App Security | Biometric or PIN app lock | TC-ST-13-04-018 |
| 4.3 App Security | Session timeout on the app | TC-ST-13-04-019 |
| 4.3 App Security | Secure storage of the session token | TC-ST-13-04-020 |
| 4.3 App Security | Lock the app | TC-ST-13-04-021 |
| 4.3 App Security | Sign out from the device | TC-ST-13-04-022 |
| 4.3 App Security | App security settings on the mobile app | TC-ST-13-04-023 |
| 4.3 App Security | Security event logging (locked, signed out) | TC-ST-13-04-024 |
| 4.3 App Security | Audit logging of the app security | TC-ST-13-04-025 |
| 4.3 App Security | Rule: The app lock uses biometrics or a PIN. | TC-ST-13-04-018 |
| 4.3 App Security | Rule: The session times out after the platform's idle period. | TC-ST-13-04-019 |
| 4.3 App Security | Rule: The session token is stored securely on the device. | TC-ST-13-04-020 |
| 4.3 App Security | Rule: Signing out from the device revokes the app session. | TC-ST-13-04-021 |
| 4.3 App Security | Rule: Security events (locked, signed out) are logged with the account and the timestamp. | TC-ST-13-04-022 |
| 4.3 App Security | Rule: The app security is audit-logged with the account and the timestamp. | TC-ST-13-04-023 |

## 4.1 App Availability and Updates

### TC-ST-13-04-001 — Mobile app on iOS and Android
**Type:** Positive
**Covers:** 4.1 → Mobile app on iOS and Android; Rule: The app is available on iOS and Android.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Mobile app on iOS and Android.
2. Observe the result and verify the full behavior: Mobile app on iOS and Android.
**Expected Result:** Mobile app on iOS and Android — delivered exactly as documented.
**Priority:** Critical

### TC-ST-13-04-002 — App updates through the app stores
**Type:** Positive
**Covers:** 4.1 → App updates through the app stores; Rule: Updates are delivered through the app stores.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: App updates through the app stores.
2. Observe the result and verify the full behavior: App updates through the app stores.
**Expected Result:** App updates through the app stores — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-003 — New version notification
**Type:** Positive
**Covers:** 4.1 → New version notification; Rule: A new version notification is shown.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: New version notification.
2. Observe the result and verify the full behavior: New version notification.
**Expected Result:** New version notification — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-004 — Minimum OS version support
**Type:** Edge
**Covers:** 4.1 → Minimum OS version support; Rule: The app supports the platform's minimum OS versions.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Minimum OS version support.
2. Observe the result and verify the full behavior: Minimum OS version support.
**Expected Result:** Minimum OS version support — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-005 — Update guidance for the OS
**Type:** Positive
**Covers:** 4.1 → Update guidance for the OS; Rule: Update events (notified, updated) are logged with the account and the timestamp.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Update guidance for the OS.
2. Observe the result and verify the full behavior: Update guidance for the OS.
**Expected Result:** Update guidance for the OS — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-006 — App version shown in the app
**Type:** Positive
**Covers:** 4.1 → App version shown in the app; Rule: The app availability and updates is audit-logged with the account and the timestamp.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: App version shown in the app.
2. Observe the result and verify the full behavior: App version shown in the app.
**Expected Result:** App version shown in the app — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-007 — Update event logging (notified, updated)
**Type:** Positive
**Covers:** 4.1 → Update event logging (notified, updated)
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Update event logging (notified.
2. Observe the result and verify the full behavior: Update event logging (notified, updated).
**Expected Result:** Update event logging (notified, updated) — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-008 — Audit logging of the app availability and updates
**Type:** Positive
**Covers:** 4.1 → Audit logging of the app availability and updates
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, perform the action associated with: Audit logging of the app availability and updates.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical

## 4.2 Push Notifications

### TC-ST-13-04-009 — Push notifications on the device
**Type:** Positive
**Covers:** 4.2 → Push notifications on the device; Rule: Push notifications require the device permission.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Push notifications on the device.
2. Observe the result and verify the full behavior: Push notifications on the device.
**Expected Result:** Push notifications on the device — delivered exactly as documented.
**Priority:** Critical

### TC-ST-13-04-010 — Study reminder push notifications
**Type:** Positive
**Covers:** 4.2 → Study reminder push notifications; Rule: The Student can enable/disable push notifications.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Study reminder push notifications.
2. Observe the result and verify the full behavior: Study reminder push notifications.
**Expected Result:** Study reminder push notifications — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-011 — Session alert push notifications
**Type:** Positive
**Covers:** 4.2 → Session alert push notifications; Rule: Notification categories can be customized.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Session alert push notifications.
2. Observe the result and verify the full behavior: Session alert push notifications.
**Expected Result:** Session alert push notifications — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-012 — Achievement push notifications
**Type:** Positive
**Covers:** 4.2 → Achievement push notifications; Rule: Push events (sent, opened, disabled) are logged with the account and the timestamp.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Achievement push notifications.
2. Observe the result and verify the full behavior: Achievement push notifications.
**Expected Result:** Achievement push notifications — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-013 — Report-ready push notifications
**Type:** Positive
**Covers:** 4.2 → Report-ready push notifications; Rule: The push notifications is audit-logged with the account and the timestamp.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Report-ready push notifications.
2. Observe the result and verify the full behavior: Report-ready push notifications.
**Expected Result:** Report-ready push notifications — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-014 — Enable/disable push notifications
**Type:** Positive
**Covers:** 4.2 → Enable/disable push notifications
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Enable/disable push notifications.
2. Observe the result and verify the full behavior: Enable/disable push notifications.
**Expected Result:** Enable/disable push notifications — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-015 — Customize notification categories
**Type:** Positive
**Covers:** 4.2 → Customize notification categories
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Customize notification categories.
2. Observe the result and verify the full behavior: Customize notification categories.
**Expected Result:** Customize notification categories — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-016 — Push event logging (sent, opened, disabled)
**Type:** Positive
**Covers:** 4.2 → Push event logging (sent, opened, disabled)
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Push event logging (sent.
2. Observe the result and verify the full behavior: Push event logging (sent, opened, disabled).
**Expected Result:** Push event logging (sent, opened, disabled) — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-017 — Audit logging of the push notifications
**Type:** Positive
**Covers:** 4.2 → Audit logging of the push notifications
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, perform the action associated with: Audit logging of the push notifications.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical

## 4.3 App Security

### TC-ST-13-04-018 — Biometric or PIN app lock
**Type:** Positive
**Covers:** 4.3 → Biometric or PIN app lock; Rule: The app lock uses biometrics or a PIN.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Biometric or PIN app lock.
2. Observe the result and verify the full behavior: Biometric or PIN app lock.
**Expected Result:** Biometric or PIN app lock — delivered exactly as documented.
**Priority:** Critical

### TC-ST-13-04-019 — Session timeout on the app
**Type:** Edge
**Covers:** 4.3 → Session timeout on the app; Rule: The session times out after the platform's idle period.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Session timeout on the app.
2. Observe the result and verify the full behavior: Session timeout on the app.
**Expected Result:** Session timeout on the app — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-020 — Secure storage of the session token
**Type:** Positive
**Covers:** 4.3 → Secure storage of the session token; Rule: The session token is stored securely on the device.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Secure storage of the session token.
2. Observe the result and verify the full behavior: Secure storage of the session token.
**Expected Result:** Secure storage of the session token — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-021 — Lock the app
**Type:** Positive
**Covers:** 4.3 → Lock the app; Rule: Signing out from the device revokes the app session.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Lock the app.
2. Observe the result and verify the full behavior: Lock the app.
**Expected Result:** Lock the app — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-022 — Sign out from the device
**Type:** Positive
**Covers:** 4.3 → Sign out from the device; Rule: Security events (locked, signed out) are logged with the account and the timestamp.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Sign out from the device.
2. Observe the result and verify the full behavior: Sign out from the device.
**Expected Result:** Sign out from the device — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-023 — App security settings on the mobile app
**Type:** Positive
**Covers:** 4.3 → App security settings on the mobile app; Rule: The app security is audit-logged with the account and the timestamp.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: App security settings on the mobile app.
2. Observe the result and verify the full behavior: App security settings on the mobile app.
**Expected Result:** App security settings on the mobile app — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-024 — Security event logging (locked, signed out)
**Type:** Positive
**Covers:** 4.3 → Security event logging (locked, signed out)
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Security event logging (locked.
2. Observe the result and verify the full behavior: Security event logging (locked, signed out).
**Expected Result:** Security event logging (locked, signed out) — delivered exactly as documented.
**Priority:** High

### TC-ST-13-04-025 — Audit logging of the app security
**Type:** Positive
**Covers:** 4.3 → Audit logging of the app security
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, perform the action associated with: Audit logging of the app security.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical
