# 1. Login & Security — Test Cases

User Type: **CSR**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: login_security.md — every feature, sub-feature, and rule covered

## Test Execution Policy

- Zero tolerance: any deviation from the documented behavior is a defect.
- Every failed test is logged with a Bug ID, the feature, the sub-feature, the expected vs actual result, and the severity; 100% of bugs are fixed before the group passes.
- 100% pass rate is required for the group to be marked complete.

## Coverage Matrix

| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 1.1 | Email + password login | TC-CSR-1-01-001 |
| 1.1 | OTP verification on login | TC-CSR-1-01-002 |
| 1.1 | Two-factor authentication (2FA) | TC-CSR-1-01-003 |
| 1.1 | Password reset via email link | TC-CSR-1-01-004 |
| 1.1 | Session timeout and auto-logout | TC-CSR-1-01-005 |
| 1.1 | Secure Login available on web and mobile | TC-CSR-1-01-006 |
| 1.1 | secure login event logging (viewed) | TC-CSR-1-01-007 |
| 1.1 | Audit logging of secure login | TC-CSR-1-01-008 |
| 1.1 | Rule: Email + password login. | TC-CSR-1-01-009 |
| 1.1 | Rule: OTP verification on login. | TC-CSR-1-01-010 |
| 1.1 | Rule: Two-factor authentication (2FA). | TC-CSR-1-01-011 |
| 1.1 | Rule: Password reset via email link. | TC-CSR-1-01-012 |
| 1.1 | Rule: Session timeout and auto-logout. | TC-CSR-1-01-013 |
| 1.2 | CSR account registration form (company name, registration number, contact) | TC-CSR-1-02-014 |
| 1.2 | Organization document upload (certificate of incorporation, CSR policy) | TC-CSR-1-02-015 |
| 1.2 | Platform verification and approval workflow | TC-CSR-1-02-016 |
| 1.2 | Email verification of the CSR contact | TC-CSR-1-02-017 |
| 1.2 | Account status: pending, verified, suspended | TC-CSR-1-02-018 |
| 1.2 | Registration & Verification available on web and mobile | TC-CSR-1-02-019 |
| 1.2 | registration & verification event logging (viewed) | TC-CSR-1-02-020 |
| 1.2 | Audit logging of registration & verification | TC-CSR-1-02-021 |
| 1.2 | Rule: CSR account registration form (company name, registration number, contact). | TC-CSR-1-02-022 |
| 1.2 | Rule: Organization document upload (certificate of incorporation, CSR policy). | TC-CSR-1-02-023 |
| 1.2 | Rule: Platform verification and approval workflow. | TC-CSR-1-02-024 |
| 1.2 | Rule: Email verification of the CSR contact. | TC-CSR-1-02-025 |
| 1.2 | Rule: Account status: pending, verified, suspended. | TC-CSR-1-02-026 |

## 1.1 Secure Login

### TC-CSR-1-01-001 — Email + password login
**Type:** Positive
**Covers:** 1.1 → Email + password login; Rule: Email + password login.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: Email + password login.
2. Observe the result and verify the full behavior: Email + password login.
**Expected Result:** Email + password login — delivered exactly as documented.
**Priority:** Critical

### TC-CSR-1-01-002 — OTP verification on login
**Type:** Positive
**Covers:** 1.1 → OTP verification on login; Rule: OTP verification on login.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: OTP verification on login.
2. Observe the result and verify the full behavior: OTP verification on login.
**Expected Result:** OTP verification on login — delivered exactly as documented.
**Priority:** High

### TC-CSR-1-01-003 — Two-factor authentication (2FA)
**Type:** Positive
**Covers:** 1.1 → Two-factor authentication (2FA); Rule: Two-factor authentication (2FA).
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: Two-factor authentication (2FA).
2. Observe the result and verify the full behavior: Two-factor authentication (2FA).
**Expected Result:** Two-factor authentication (2FA) — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-01-004 — Password reset via email link
**Type:** Positive
**Covers:** 1.1 → Password reset via email link; Rule: Password reset via email link.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: Password reset via email link.
2. Observe the result and verify the full behavior: Password reset via email link.
**Expected Result:** Password reset via email link — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-01-005 — Session timeout and auto-logout
**Type:** Positive
**Covers:** 1.1 → Session timeout and auto-logout; Rule: Session timeout and auto-logout.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: Session timeout and auto-logout.
2. Observe the result and verify the full behavior: Session timeout and auto-logout.
**Expected Result:** Session timeout and auto-logout — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-01-006 — Secure Login available on web and mobile
**Type:** Positive
**Covers:** 1.1 → Secure Login available on web and mobile; Rule: Email + password login.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: Secure Login available on web and mobile.
2. Observe the result and verify the full behavior: Secure Login available on web and mobile.
**Expected Result:** Secure Login available on web and mobile — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-01-007 — secure login event logging (viewed)
**Type:** Positive
**Covers:** 1.1 → secure login event logging (viewed); Rule: OTP verification on login.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: secure login event logging (viewed).
2. Observe the result and verify the full behavior: secure login event logging (viewed).
**Expected Result:** secure login event logging (viewed) — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-01-008 — Audit logging of secure login
**Type:** Positive
**Covers:** 1.1 → Audit logging of secure login; Rule: Two-factor authentication (2FA).
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: Audit logging of secure login.
2. Observe the result and verify the full behavior: Audit logging of secure login.
**Expected Result:** Audit logging of secure login — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-01-009 — Rule: Email + password login.
**Type:** Positive
**Covers:** 1.1 → Rule: Email + password login.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform the action that triggers the rule: Email + password login.
2. Observe the result and verify the full behavior: Email + password login.
**Expected Result:** Email + password login. — delivered exactly as documented.
**Priority:** Critical

### TC-CSR-1-01-010 — Rule: OTP verification on login.
**Type:** Positive
**Covers:** 1.1 → Rule: OTP verification on login.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform the action that triggers the rule: OTP verification on login.
2. Observe the result and verify the full behavior: OTP verification on login.
**Expected Result:** OTP verification on login. — delivered exactly as documented.
**Priority:** High

### TC-CSR-1-01-011 — Rule: Two-factor authentication (2FA).
**Type:** Positive
**Covers:** 1.1 → Rule: Two-factor authentication (2FA).
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform the action that triggers the rule: Two-factor authentication (2FA).
2. Observe the result and verify the full behavior: Two-factor authentication (2FA).
**Expected Result:** Two-factor authentication (2FA). — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-01-012 — Rule: Password reset via email link.
**Type:** Positive
**Covers:** 1.1 → Rule: Password reset via email link.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform the action that triggers the rule: Password reset via email link.
2. Observe the result and verify the full behavior: Password reset via email link.
**Expected Result:** Password reset via email link. — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-01-013 — Rule: Session timeout and auto-logout.
**Type:** Positive
**Covers:** 1.1 → Rule: Session timeout and auto-logout.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform the action that triggers the rule: Session timeout and auto-logout.
2. Observe the result and verify the full behavior: Session timeout and auto-logout.
**Expected Result:** Session timeout and auto-logout. — delivered exactly as documented.
**Priority:** Medium

## 1.2 Registration & Verification

### TC-CSR-1-02-014 — CSR account registration form (company name, registration number, contact)
**Type:** Positive
**Covers:** 1.2 → CSR account registration form (company name, registration number, contact); Rule: CSR account registration form (company name, registration number, contact).
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: CSR account registration form (company name, registration number, contact).
2. Observe the result and verify the full behavior: CSR account registration form (company name, registration number, contact).
**Expected Result:** CSR account registration form (company name, registration number, contact) — delivered exactly as documented.
**Priority:** Critical

### TC-CSR-1-02-015 — Organization document upload (certificate of incorporation, CSR policy)
**Type:** Positive
**Covers:** 1.2 → Organization document upload (certificate of incorporation, CSR policy); Rule: Organization document upload (certificate of incorporation, CSR policy).
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: Organization document upload (certificate of incorporation, CSR policy).
2. Observe the result and verify the full behavior: Organization document upload (certificate of incorporation, CSR policy).
**Expected Result:** Organization document upload (certificate of incorporation, CSR policy) — delivered exactly as documented.
**Priority:** High

### TC-CSR-1-02-016 — Platform verification and approval workflow
**Type:** Positive
**Covers:** 1.2 → Platform verification and approval workflow; Rule: Platform verification and approval workflow.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: Platform verification and approval workflow.
2. Observe the result and verify the full behavior: Platform verification and approval workflow.
**Expected Result:** Platform verification and approval workflow — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-02-017 — Email verification of the CSR contact
**Type:** Positive
**Covers:** 1.2 → Email verification of the CSR contact; Rule: Email verification of the CSR contact.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: Email verification of the CSR contact.
2. Observe the result and verify the full behavior: Email verification of the CSR contact.
**Expected Result:** Email verification of the CSR contact — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-02-018 — Account status: pending, verified, suspended
**Type:** Positive
**Covers:** 1.2 → Account status: pending, verified, suspended; Rule: Account status: pending, verified, suspended.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: Account status: pending, verified, suspended.
2. Observe the result and verify the full behavior: Account status: pending, verified, suspended.
**Expected Result:** Account status: pending, verified, suspended — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-02-019 — Registration & Verification available on web and mobile
**Type:** Positive
**Covers:** 1.2 → Registration & Verification available on web and mobile; Rule: CSR account registration form (company name, registration number, contact).
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: Registration & Verification available on web and mobile.
2. Observe the result and verify the full behavior: Registration & Verification available on web and mobile.
**Expected Result:** Registration & Verification available on web and mobile — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-02-020 — registration & verification event logging (viewed)
**Type:** Positive
**Covers:** 1.2 → registration & verification event logging (viewed); Rule: Organization document upload (certificate of incorporation, CSR policy).
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: registration & verification event logging (viewed).
2. Observe the result and verify the full behavior: registration & verification event logging (viewed).
**Expected Result:** registration & verification event logging (viewed) — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-02-021 — Audit logging of registration & verification
**Type:** Positive
**Covers:** 1.2 → Audit logging of registration & verification; Rule: Platform verification and approval workflow.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform: Audit logging of registration & verification.
2. Observe the result and verify the full behavior: Audit logging of registration & verification.
**Expected Result:** Audit logging of registration & verification — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-02-022 — Rule: CSR account registration form (company name, registration number, contact).
**Type:** Positive
**Covers:** 1.2 → Rule: CSR account registration form (company name, registration number, contact).
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform the action that triggers the rule: CSR account registration form (company name, registration number, contact).
2. Observe the result and verify the full behavior: CSR account registration form (company name, registration number, contact).
**Expected Result:** CSR account registration form (company name, registration number, contact). — delivered exactly as documented.
**Priority:** Critical

### TC-CSR-1-02-023 — Rule: Organization document upload (certificate of incorporation, CSR policy).
**Type:** Positive
**Covers:** 1.2 → Rule: Organization document upload (certificate of incorporation, CSR policy).
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform the action that triggers the rule: Organization document upload (certificate of incorporation, CSR policy).
2. Observe the result and verify the full behavior: Organization document upload (certificate of incorporation, CSR policy).
**Expected Result:** Organization document upload (certificate of incorporation, CSR policy). — delivered exactly as documented.
**Priority:** High

### TC-CSR-1-02-024 — Rule: Platform verification and approval workflow.
**Type:** Positive
**Covers:** 1.2 → Rule: Platform verification and approval workflow.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform the action that triggers the rule: Platform verification and approval workflow.
2. Observe the result and verify the full behavior: Platform verification and approval workflow.
**Expected Result:** Platform verification and approval workflow. — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-02-025 — Rule: Email verification of the CSR contact.
**Type:** Positive
**Covers:** 1.2 → Rule: Email verification of the CSR contact.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform the action that triggers the rule: Email verification of the CSR contact.
2. Observe the result and verify the full behavior: Email verification of the CSR contact.
**Expected Result:** Email verification of the CSR contact. — delivered exactly as documented.
**Priority:** Medium

### TC-CSR-1-02-026 — Rule: Account status: pending, verified, suspended.
**Type:** Positive
**Covers:** 1.2 → Rule: Account status: pending, verified, suspended.
**Preconditions:** A CSR account is active and the CSR is in the state required for this behavior.
**Steps:**
1. As a CSR, set up the precondition and perform the action that triggers the rule: Account status: pending, verified, suspended.
2. Observe the result and verify the full behavior: Account status: pending, verified, suspended.
**Expected Result:** Account status: pending, verified, suspended. — delivered exactly as documented.
**Priority:** Medium
