# 4. Session Management & Privacy — Test Cases

User Type: **Student**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: session_management_privacy.md — every feature, sub-feature, and rule covered

---

## Test Execution Policy
- Zero tolerance: any deviation from documented behavior = FAILED = bug
- Every bug is immediately logged/reported (Bug ID, feature, sub-feature, expected vs actual, severity) and fixed 100% before the group passes
- Feature group passes only at 100% test pass rate

## Coverage Matrix
| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 4.1 Session Management | Active sessions list: device type, browser/app, location, last active time, current session marker | TC-ST-01-04-001 |
| 4.1 Session Management | Sign out of a single session from the list | TC-ST-01-04-002 |
| 4.1 Session Management | "Sign out everywhere" to terminate all sessions except the current one | TC-ST-01-04-003 |
| 4.1 Session Management | Inactivity timeout: idle sessions are automatically signed out after a policy-defined period | TC-ST-01-04-004 |
| 4.1 Session Management | Concurrency limit: a maximum number of simultaneous sessions per account | TC-ST-01-04-005 |
| 4.1 Session Management | "Remember me" behavior: extended session persistence on trusted devices | TC-ST-01-04-006 |
| 4.1 Session Management | Session termination on password reset and on account suspension | TC-ST-01-04-007 |
| 4.1 Session Management | New-device login notification (email alert when a new device signs in) | TC-ST-01-04-008 |
| 4.1 Session Management | Session event logging (created, extended, terminated, timeout) | TC-ST-01-04-009 |
| 4.1 Session Management | Audit logging of the session management | TC-ST-01-04-010 |
| 4.1 Session Management | Rule: The current session is never terminated by "Sign out everywhere". | TC-ST-01-04-001 |
| 4.1 Session Management | Rule: Inactivity timeouts are policy-defined; the Student is notified when a session expires due to inactivity. | TC-ST-01-04-002 |
| 4.1 Session Management | Rule: The concurrency limit caps simultaneous sessions; exceeding it terminates the oldest session. | TC-ST-01-04-003 |
| 4.1 Session Management | Rule: A password reset or account suspension terminates all sessions immediately. | TC-ST-01-04-004 |
| 4.1 Session Management | Rule: New-device logins trigger an email notification to the registered address. | TC-ST-01-04-005 |
| 4.1 Session Management | Rule: Session events (created, extended, terminated, timeout) are logged with device, IP, and timestamp. | TC-ST-01-04-006 |
| 4.1 Session Management | Rule: The session management is audit-logged with the account, the action, and the timestamp. | TC-ST-01-04-007 |
| 4.2 Privacy & Consent | Privacy policy access from the profile and at registration | TC-ST-01-04-011 |
| 4.2 Privacy & Consent | Data collection summary: what data is collected and why | TC-ST-01-04-012 |
| 4.2 Privacy & Consent | Communication preference management (email, SMS, in-app) per category | TC-ST-01-04-013 |
| 4.2 Privacy & Consent | Data portability: request a copy of the Student's data in a standard format | TC-ST-01-04-014 |
| 4.2 Privacy & Consent | Account deletion request with a confirmation and a cooling-off period | TC-ST-01-04-015 |
| 4.2 Privacy & Consent | Consent records: what consents were given and when | TC-ST-01-04-016 |
| 4.2 Privacy & Consent | Minor-specific consent: parent consent status visible where applicable | TC-ST-01-04-017 |
| 4.2 Privacy & Consent | Deletion handling: data removed or anonymized per the retention policy | TC-ST-01-04-018 |
| 4.2 Privacy & Consent | Consent and deletion event logging | TC-ST-01-04-019 |
| 4.2 Privacy & Consent | Audit logging of the privacy and consent | TC-ST-01-04-020 |
| 4.2 Privacy & Consent | Rule: The privacy policy is accessible at registration and from the profile at all times. | TC-ST-01-04-011 |
| 4.2 Privacy & Consent | Rule: Communication preferences are per-channel and per-category; changing them takes effect immediately. | TC-ST-01-04-012 |
| 4.2 Privacy & Consent | Rule: A data portability request is fulfilled within the policy window in a standard, machine-readable format. | TC-ST-01-04-013 |
| 4.2 Privacy & Consent | Rule: Account deletion requires password confirmation and a cooling-off period during which it can be cancelled. | TC-ST-01-04-014 |
| 4.2 Privacy & Consent | Rule: After deletion, personal data is removed or anonymized per the retention policy; legally required records are retained as mandated. | TC-ST-01-04-015 |
| 4.2 Privacy & Consent | Rule: For minors, parent consent status is tracked and visible where applicable. | TC-ST-01-04-016 |
| 4.2 Privacy & Consent | Rule: Consent and deletion events are logged with timestamp and the specific consent or action. | TC-ST-01-04-017 |
| 4.2 Privacy & Consent | Rule: The privacy and consent actions are audit-logged with the account, the action, and the timestamp. | TC-ST-01-04-018 |

## 4.1 Session Management

### TC-ST-01-04-001 — Active sessions list: device type, browser/app, location, last active time, current session marker
**Type:** Positive
**Covers:** 4.1 → Active sessions list: device type, browser/app, location, last active time, current session marker; Rule: The current session is never terminated by "Sign out everywhere".
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Active sessions list: device type.
2. Observe the result and verify the full behavior: Active sessions list: device type, browser/app, location, last active time, current session marker.
**Expected Result:** Active sessions list: device type, browser/app, location, last active time, current session marker — delivered exactly as documented.
**Priority:** Critical

### TC-ST-01-04-002 — Sign out of a single session from the list
**Type:** Positive
**Covers:** 4.1 → Sign out of a single session from the list; Rule: Inactivity timeouts are policy-defined; the Student is notified when a session expires due to inactivity.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Sign out of a single session from the list.
2. Observe the result and verify the full behavior: Sign out of a single session from the list.
**Expected Result:** Sign out of a single session from the list — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-003 — "Sign out everywhere" to terminate all sessions except the current one
**Type:** Positive
**Covers:** 4.1 → "Sign out everywhere" to terminate all sessions except the current one; Rule: The concurrency limit caps simultaneous sessions; exceeding it terminates the oldest session.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: "Sign out everywhere" to terminate all sessions except the current one.
2. Observe the result and verify the full behavior: "Sign out everywhere" to terminate all sessions except the current one.
**Expected Result:** "Sign out everywhere" to terminate all sessions except the current one — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-004 — Inactivity timeout: idle sessions are automatically signed out after a policy-defined period
**Type:** Edge
**Covers:** 4.1 → Inactivity timeout: idle sessions are automatically signed out after a policy-defined period; Rule: A password reset or account suspension terminates all sessions immediately.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Inactivity timeout: idle sessions are automatically signed out after a policy-defined period.
2. Observe the result and verify the full behavior: Inactivity timeout: idle sessions are automatically signed out after a policy-defined period.
**Expected Result:** Inactivity timeout: idle sessions are automatically signed out after a policy-defined period — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-005 — Concurrency limit: a maximum number of simultaneous sessions per account
**Type:** Edge
**Covers:** 4.1 → Concurrency limit: a maximum number of simultaneous sessions per account; Rule: New-device logins trigger an email notification to the registered address.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Concurrency limit: a maximum number of simultaneous sessions per account.
2. Observe the result and verify the full behavior: Concurrency limit: a maximum number of simultaneous sessions per account.
**Expected Result:** Concurrency limit: a maximum number of simultaneous sessions per account — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-006 — "Remember me" behavior: extended session persistence on trusted devices
**Type:** Positive
**Covers:** 4.1 → "Remember me" behavior: extended session persistence on trusted devices; Rule: Session events (created, extended, terminated, timeout) are logged with device, IP, and timestamp.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: "Remember me" behavior: extended session persistence on trusted devices.
2. Observe the result and verify the full behavior: "Remember me" behavior: extended session persistence on trusted devices.
**Expected Result:** "Remember me" behavior: extended session persistence on trusted devices — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-007 — Session termination on password reset and on account suspension
**Type:** Positive
**Covers:** 4.1 → Session termination on password reset and on account suspension; Rule: The session management is audit-logged with the account, the action, and the timestamp.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Session termination on password reset and on account suspension.
2. Observe the result and verify the full behavior: Session termination on password reset and on account suspension.
**Expected Result:** Session termination on password reset and on account suspension — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-008 — New-device login notification (email alert when a new device signs in)
**Type:** Positive
**Covers:** 4.1 → New-device login notification (email alert when a new device signs in)
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: New-device login notification (email alert when a new device signs in).
2. Observe the result and verify the full behavior: New-device login notification (email alert when a new device signs in).
**Expected Result:** New-device login notification (email alert when a new device signs in) — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-009 — Session event logging (created, extended, terminated, timeout)
**Type:** Edge
**Covers:** 4.1 → Session event logging (created, extended, terminated, timeout)
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Session event logging (created.
2. Observe the result and verify the full behavior: Session event logging (created, extended, terminated, timeout).
**Expected Result:** Session event logging (created, extended, terminated, timeout) — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-010 — Audit logging of the session management
**Type:** Positive
**Covers:** 4.1 → Audit logging of the session management
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, perform the action associated with: Audit logging of the session management.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical

## 4.2 Privacy & Consent

### TC-ST-01-04-011 — Privacy policy access from the profile and at registration
**Type:** Positive
**Covers:** 4.2 → Privacy policy access from the profile and at registration; Rule: The privacy policy is accessible at registration and from the profile at all times.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Privacy policy access from the profile and at registration.
2. Observe the result and verify the full behavior: Privacy policy access from the profile and at registration.
**Expected Result:** Privacy policy access from the profile and at registration — delivered exactly as documented.
**Priority:** Critical

### TC-ST-01-04-012 — Data collection summary: what data is collected and why
**Type:** Positive
**Covers:** 4.2 → Data collection summary: what data is collected and why; Rule: Communication preferences are per-channel and per-category; changing them takes effect immediately.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Data collection summary: what data is collected and why.
2. Observe the result and verify the full behavior: Data collection summary: what data is collected and why.
**Expected Result:** Data collection summary: what data is collected and why — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-013 — Communication preference management (email, SMS, in-app) per category
**Type:** Positive
**Covers:** 4.2 → Communication preference management (email, SMS, in-app) per category; Rule: A data portability request is fulfilled within the policy window in a standard, machine-readable format.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Communication preference management (email.
2. Observe the result and verify the full behavior: Communication preference management (email, SMS, in-app) per category.
**Expected Result:** Communication preference management (email, SMS, in-app) per category — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-014 — Data portability: request a copy of the Student's data in a standard format
**Type:** Positive
**Covers:** 4.2 → Data portability: request a copy of the Student's data in a standard format; Rule: Account deletion requires password confirmation and a cooling-off period during which it can be cancelled.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Data portability: request a copy of the Student's data in a standard format.
2. Observe the result and verify the full behavior: Data portability: request a copy of the Student's data in a standard format.
**Expected Result:** Data portability: request a copy of the Student's data in a standard format — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-015 — Account deletion request with a confirmation and a cooling-off period
**Type:** Positive
**Covers:** 4.2 → Account deletion request with a confirmation and a cooling-off period; Rule: After deletion, personal data is removed or anonymized per the retention policy; legally required records are retained as mandated.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Account deletion request with a confirmation and a cooling-off period.
2. Observe the result and verify the full behavior: Account deletion request with a confirmation and a cooling-off period.
**Expected Result:** Account deletion request with a confirmation and a cooling-off period — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-016 — Consent records: what consents were given and when
**Type:** Positive
**Covers:** 4.2 → Consent records: what consents were given and when; Rule: For minors, parent consent status is tracked and visible where applicable.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Consent records: what consents were given and when.
2. Observe the result and verify the full behavior: Consent records: what consents were given and when.
**Expected Result:** Consent records: what consents were given and when — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-017 — Minor-specific consent: parent consent status visible where applicable
**Type:** Positive
**Covers:** 4.2 → Minor-specific consent: parent consent status visible where applicable; Rule: Consent and deletion events are logged with timestamp and the specific consent or action.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Minor-specific consent: parent consent status visible where applicable.
2. Observe the result and verify the full behavior: Minor-specific consent: parent consent status visible where applicable.
**Expected Result:** Minor-specific consent: parent consent status visible where applicable — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-018 — Deletion handling: data removed or anonymized per the retention policy
**Type:** Positive
**Covers:** 4.2 → Deletion handling: data removed or anonymized per the retention policy; Rule: The privacy and consent actions are audit-logged with the account, the action, and the timestamp.
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Deletion handling: data removed or anonymized per the retention policy.
2. Observe the result and verify the full behavior: Deletion handling: data removed or anonymized per the retention policy.
**Expected Result:** Deletion handling: data removed or anonymized per the retention policy — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-019 — Consent and deletion event logging
**Type:** Positive
**Covers:** 4.2 → Consent and deletion event logging
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, set up the precondition and perform: Consent and deletion event logging.
2. Observe the result and verify the full behavior: Consent and deletion event logging.
**Expected Result:** Consent and deletion event logging — delivered exactly as documented.
**Priority:** High

### TC-ST-01-04-020 — Audit logging of the privacy and consent
**Type:** Positive
**Covers:** 4.2 → Audit logging of the privacy and consent
**Preconditions:** A Student account is active and the Student is in the state required for this behavior.
**Steps:**
1. As a Student, perform the action associated with: Audit logging of the privacy and consent.
2. Open the relevant activity / audit log and verify the event is recorded with the account, the action, and the timestamp.
**Expected Result:** The action is audit-logged — the account, the action, and the timestamp are recorded.
**Priority:** Critical
