# 1. Parent Login — Test Cases

User Type: **Parent**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: parent_login.md — every feature, sub-feature, and rule covered

---

## Test Execution Policy
- Zero tolerance: any deviation from documented behavior = FAILED = bug
- Every bug is immediately logged/reported (Bug ID, feature, sub-feature, expected vs actual, severity) and fixed 100% before the group passes
- Feature group passes only at 100% test pass rate

## Coverage Matrix
| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 1.1 Email and Password Login | Login with registered email and password | TC-PT-1-01-001 |
| 1.1 Email and Password Login | Email format validation | TC-PT-1-01-002 |
| 1.1 Email and Password Login | Password validation | TC-PT-1-01-003 |
| 1.1 Email and Password Login | Error message for incorrect credentials | TC-PT-1-01-004 |
| 1.1 Email and Password Login | Rate limiting on repeated failed attempts | TC-PT-1-01-005 |
| 1.1 Email and Password Login | Account lockout after repeated failures | TC-PT-1-01-006 |
| 1.1 Email and Password Login | Secure credential handling | TC-PT-1-01-007 |
| 1.1 Email and Password Login | Login event logging (success, failure) | TC-PT-1-01-008 |
| 1.1 Email and Password Login | Audit logging of the email and password login | TC-PT-1-01-009 |
| 1.1 Email and Password Login | Rule: The email must be in a valid format. | TC-PT-1-01-001 |
| 1.1 Email and Password Login | Rule: Incorrect credentials show a generic error message. | TC-PT-1-01-002 |
| 1.1 Email and Password Login | Rule: Repeated failed attempts are rate-limited. | TC-PT-1-01-003 |
| 1.1 Email and Password Login | Rule: The account is locked after the platform's failure threshold. | TC-PT-1-01-004 |
| 1.1 Email and Password Login | Rule: Login events (success, failure) are logged with the account and the timestamp. | TC-PT-1-01-005 |
| 1.1 Email and Password Login | Rule: The email and password login is audit-logged with the account and the timestamp. | TC-PT-1-01-006 |
| 1.2 One-Time Password (OTP) Login | Request an OTP to the registered email or phone | TC-PT-1-01-010 |
| 1.2 One-Time Password (OTP) Login | Enter the 6-digit OTP code | TC-PT-1-01-011 |
| 1.2 One-Time Password (OTP) Login | OTP expiry (short window) | TC-PT-1-01-012 |
| 1.2 One-Time Password (OTP) Login | Regenerate the OTP | TC-PT-1-01-013 |
| 1.2 One-Time Password (OTP) Login | OTP attempt limit | TC-PT-1-01-014 |
| 1.2 One-Time Password (OTP) Login | OTP verification | TC-PT-1-01-015 |
| 1.2 One-Time Password (OTP) Login | OTP event logging (requested, verified, expired) | TC-PT-1-01-016 |
| 1.2 One-Time Password (OTP) Login | Audit logging of the one-time password login | TC-PT-1-01-017 |
| 1.2 One-Time Password (OTP) Login | Rule: The OTP is a 6-digit code. | TC-PT-1-01-010 |
| 1.2 One-Time Password (OTP) Login | Rule: The OTP expires after the platform's window. | TC-PT-1-01-011 |
| 1.2 One-Time Password (OTP) Login | Rule: The OTP has an attempt limit. | TC-PT-1-01-012 |
| 1.2 One-Time Password (OTP) Login | Rule: A new OTP can be requested. | TC-PT-1-01-013 |
| 1.2 One-Time Password (OTP) Login | Rule: OTP events (requested, verified, expired) are logged with the account and the timestamp. | TC-PT-1-01-014 |
| 1.2 One-Time Password (OTP) Login | Rule: The one-time password login is audit-logged with the account and the timestamp. | TC-PT-1-01-015 |
| 1.3 Social Login | Sign in with a social account (Google, Apple) | TC-PT-1-01-018 |
| 1.3 Social Login | Social account authorization | TC-PT-1-01-019 |
| 1.3 Social Login | Link the social account on first use | TC-PT-1-01-020 |
| 1.3 Social Login | Social login event logging (authorized, linked) | TC-PT-1-01-021 |
| 1.3 Social Login | Unlink a social account | TC-PT-1-01-022 |
| 1.3 Social Login | Social login available on web and mobile | TC-PT-1-01-023 |
| 1.3 Social Login | Audit logging of the social login | TC-PT-1-01-024 |
| 1.3 Social Login | Rule: The social login uses the provider's authorization. | TC-PT-1-01-018 |
| 1.3 Social Login | Rule: The social account is linked on first use. | TC-PT-1-01-019 |
| 1.3 Social Login | Rule: A social account can be unlinked. | TC-PT-1-01-020 |
| 1.3 Social Login | Rule: Social login events (authorized, linked) are logged with the account and the timestamp. | TC-PT-1-01-021 |
| 1.3 Social Login | Rule: The social login is audit-logged with the account and the timestamp. | TC-PT-1-01-022 |

## 1.1 Email and Password Login

### TC-PT-1-01-001 — Login with registered email and password
**Type:** Positive
**Covers:** 1.1 → Login with registered email and password; Rule: The email must be in a valid format.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Login with registered email and password.
2. Observe the result and verify the full behavior: Login with registered email and password.
**Expected Result:** Login with registered email and password — delivered exactly as documented.
**Priority:** Critical

### TC-PT-1-01-002 — Email format validation
**Type:** Edge
**Covers:** 1.1 → Email format validation; Rule: Incorrect credentials show a generic error message.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Email format validation.
2. Observe the result and verify the full behavior: Email format validation.
**Expected Result:** Email format validation — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-003 — Password validation
**Type:** Edge
**Covers:** 1.1 → Password validation; Rule: Repeated failed attempts are rate-limited.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Password validation.
2. Observe the result and verify the full behavior: Password validation.
**Expected Result:** Password validation — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-004 — Error message for incorrect credentials
**Type:** Positive
**Covers:** 1.1 → Error message for incorrect credentials; Rule: The account is locked after the platform's failure threshold.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Error message for incorrect credentials.
2. Observe the result and verify the full behavior: Error message for incorrect credentials.
**Expected Result:** Error message for incorrect credentials — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-005 — Rate limiting on repeated failed attempts
**Type:** Edge
**Covers:** 1.1 → Rate limiting on repeated failed attempts; Rule: Login events (success, failure) are logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Rate limiting on repeated failed attempts.
2. Observe the result and verify the full behavior: Rate limiting on repeated failed attempts.
**Expected Result:** Rate limiting on repeated failed attempts — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-006 — Account lockout after repeated failures
**Type:** Positive
**Covers:** 1.1 → Account lockout after repeated failures; Rule: The email and password login is audit-logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Account lockout after repeated failures.
2. Observe the result and verify the full behavior: Account lockout after repeated failures.
**Expected Result:** Account lockout after repeated failures — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-007 — Secure credential handling
**Type:** Positive
**Covers:** 1.1 → Secure credential handling
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Secure credential handling.
2. Observe the result and verify the full behavior: Secure credential handling.
**Expected Result:** Secure credential handling — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-008 — Login event logging (success, failure)
**Type:** Positive
**Covers:** 1.1 → Login event logging (success, failure)
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Login event logging (success.
2. Observe the result and verify the full behavior: Login event logging (success, failure).
**Expected Result:** Login event logging (success, failure) — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-009 — Audit logging of the email and password login
**Type:** Positive
**Covers:** 1.1 → Audit logging of the email and password login
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, perform the action associated with: Audit logging of the email and password login.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical

## 1.2 One-Time Password (OTP) Login

### TC-PT-1-01-010 — Request an OTP to the registered email or phone
**Type:** Positive
**Covers:** 1.2 → Request an OTP to the registered email or phone; Rule: The OTP is a 6-digit code.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Request an OTP to the registered email or phone.
2. Observe the result and verify the full behavior: Request an OTP to the registered email or phone.
**Expected Result:** Request an OTP to the registered email or phone — delivered exactly as documented.
**Priority:** Critical

### TC-PT-1-01-011 — Enter the 6-digit OTP code
**Type:** Positive
**Covers:** 1.2 → Enter the 6-digit OTP code; Rule: The OTP expires after the platform's window.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Enter the 6-digit OTP code.
2. Observe the result and verify the full behavior: Enter the 6-digit OTP code.
**Expected Result:** Enter the 6-digit OTP code — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-012 — OTP expiry (short window)
**Type:** Edge
**Covers:** 1.2 → OTP expiry (short window); Rule: The OTP has an attempt limit.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: OTP expiry (short window).
2. Observe the result and verify the full behavior: OTP expiry (short window).
**Expected Result:** OTP expiry (short window) — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-013 — Regenerate the OTP
**Type:** Positive
**Covers:** 1.2 → Regenerate the OTP; Rule: A new OTP can be requested.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Regenerate the OTP.
2. Observe the result and verify the full behavior: Regenerate the OTP.
**Expected Result:** Regenerate the OTP — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-014 — OTP attempt limit
**Type:** Edge
**Covers:** 1.2 → OTP attempt limit; Rule: OTP events (requested, verified, expired) are logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: OTP attempt limit.
2. Observe the result and verify the full behavior: OTP attempt limit.
**Expected Result:** OTP attempt limit — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-015 — OTP verification
**Type:** Positive
**Covers:** 1.2 → OTP verification; Rule: The one-time password login is audit-logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: OTP verification.
2. Observe the result and verify the full behavior: OTP verification.
**Expected Result:** OTP verification — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-016 — OTP event logging (requested, verified, expired)
**Type:** Edge
**Covers:** 1.2 → OTP event logging (requested, verified, expired)
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: OTP event logging (requested.
2. Observe the result and verify the full behavior: OTP event logging (requested, verified, expired).
**Expected Result:** OTP event logging (requested, verified, expired) — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-017 — Audit logging of the one-time password login
**Type:** Positive
**Covers:** 1.2 → Audit logging of the one-time password login
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, perform the action associated with: Audit logging of the one-time password login.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical

## 1.3 Social Login

### TC-PT-1-01-018 — Sign in with a social account (Google, Apple)
**Type:** Positive
**Covers:** 1.3 → Sign in with a social account (Google, Apple); Rule: The social login uses the provider's authorization.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Sign in with a social account (Google.
2. Observe the result and verify the full behavior: Sign in with a social account (Google, Apple).
**Expected Result:** Sign in with a social account (Google, Apple) — delivered exactly as documented.
**Priority:** Critical

### TC-PT-1-01-019 — Social account authorization
**Type:** Positive
**Covers:** 1.3 → Social account authorization; Rule: The social account is linked on first use.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Social account authorization.
2. Observe the result and verify the full behavior: Social account authorization.
**Expected Result:** Social account authorization — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-020 — Link the social account on first use
**Type:** Positive
**Covers:** 1.3 → Link the social account on first use; Rule: A social account can be unlinked.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Link the social account on first use.
2. Observe the result and verify the full behavior: Link the social account on first use.
**Expected Result:** Link the social account on first use — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-021 — Social login event logging (authorized, linked)
**Type:** Positive
**Covers:** 1.3 → Social login event logging (authorized, linked); Rule: Social login events (authorized, linked) are logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Social login event logging (authorized.
2. Observe the result and verify the full behavior: Social login event logging (authorized, linked).
**Expected Result:** Social login event logging (authorized, linked) — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-022 — Unlink a social account
**Type:** Positive
**Covers:** 1.3 → Unlink a social account; Rule: The social login is audit-logged with the account and the timestamp.
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Unlink a social account.
2. Observe the result and verify the full behavior: Unlink a social account.
**Expected Result:** Unlink a social account — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-023 — Social login available on web and mobile
**Type:** Positive
**Covers:** 1.3 → Social login available on web and mobile
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, set up the precondition and perform: Social login available on web and mobile.
2. Observe the result and verify the full behavior: Social login available on web and mobile.
**Expected Result:** Social login available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-PT-1-01-024 — Audit logging of the social login
**Type:** Positive
**Covers:** 1.3 → Audit logging of the social login
**Preconditions:** A Parent account is active and the Parent is in the state required for this behavior.
**Steps:**
1. As a Parent, perform the action associated with: Audit logging of the social login.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical
