> For the complete documentation index, see [llms.txt](https://ultimatewebsolutions.gitbook.io/qa-knowledge-base/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ultimatewebsolutions.gitbook.io/qa-knowledge-base/login-form-testing-example.md).

# Login form testing example

What would you test on this login screen?

<div align="left"><figure><img src="https://68936076-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKa5W2q6HA7EDVl7m4OHV%2Fuploads%2F081KDzFiL1qY03MlCU4D%2Flogin.png?alt=media&amp;token=16e0b62c-a29b-4159-bf21-2772392bec63" alt=""><figcaption></figcaption></figure></div>

### 1. Functional testing — start with the happy path

**Valid credentials:**

* Valid username + valid password → successful login
* Valid email + valid password → successful login
* User is redirected to the correct page
* Correct user/account information is displayed
* Session is created correctly

This is the **first thing I'd test**.

### 2. Negative testing

Try:

* Invalid username
* Invalid email
* Invalid password
* Username doesn't exist
* Correct username + wrong password
* Both fields empty
* Username empty + password populated
* Password empty + username populated
* Leading/trailing spaces
* Upper/lowercase differences
* Very long username
* Very long password
* Special characters

And importantly:

> **Does the application give an appropriate error message without revealing sensitive information?**

For example, ideally don't reveal whether a particular email address exists if that would enable account enumeration.

### 3. Boundary / input validation

I'd investigate the allowed input rules:

* Minimum username length
* Maximum username length
* Minimum password length
* Maximum password length
* Unicode characters
* Special characters
* Copy/paste into password
* Spaces
* SQL injection strings
* HTML/JavaScript injection strings

### 4. "Keep me signed in"

This is particularly interesting because the page has a **Keep me signed in** option.

I'd test:

```
Unchecked   
↓
Login
↓
Close browser
↓
Open again
↓
Should the session still exist?
```

Then:

```
Checked
↓
Login
↓
Close browser
↓
Open again
↓
Is the user still authenticated?
```

I'd also test logout and session expiration.

### 5. Forgot password

The page provides a **Forgot your password?** flow.

I'd test:

* Valid email
* Invalid email
* Non-existent email
* Empty email
* Password reset email received
* Reset link works
* Expired reset link
* Reset link used twice
* New password rules
* Old password no longer works
* New password works
* Password reset token security

### 6. Security testing 🔐

For a login page, this is **high priority**.

I'd consider:

* HTTPS
* Password not visible in plain text
* Password not appearing in URL
* Brute-force protection
* Rate limiting
* Account lockout / throttling
* Session management
* Session timeout
* Secure cookies
* CSRF protection
* XSS
* SQL injection
* Authentication bypass
* Authorization after login
* User cannot access another user's data by manipulating URLs

For a customer portal, I'd give security **high priority** because authentication protects potentially sensitive customer information.

### 7. UI / usability

I'd check:

* Labels are clear
* Password is masked
* Login button is clearly visible
* Error messages are understandable
* Keyboard navigation works
* Tab order is logical
* Enter key submits the form
* Focus is visible
* Responsive design
* Mobile/tablet/desktop
* Different browsers

### 8. Performance

This connects directly to your previous question.

I'd ask:

> **"How many users are expected to log in concurrently, and what are the peak login periods?"**

Then I could determine the appropriate performance testing.

For example:

* Normal load → 500 concurrent users
* Peak load → 2,000 concurrent users
* Stress → gradually exceed expected capacity
* Spike → sudden large increase in users

I'd measure:

* Response time
* Throughput
* Error rate
* CPU/memory
* Database performance
* Authentication service performance
