A semi-automated testing method for the automatic filling function of a password manager

Through semi-automated testing methods, combined with end-to-end testing tools and OCR technology, the time-consuming and labor-consuming problem of automatic filling function testing of password managers is solved, and efficient and reliable test results and data security are achieved.

CN119415395BActive Publication Date: 2025-07-11NANKAI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411532475.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-30
Publication Date
2025-07-11
Estimated Expiration
2044-10-30

AI Technical Summary

Technical Problem

The test method of the automatic filling function of password managers in the prior art is time-consuming and labor-intensive, and the dependence on manual operations leads to poor reliability and repeatability, making it impossible to effectively test the interaction between browser plug-ins and web websites.

Method used

The semi-automated testing method is adopted, combined with end-to-end testing tools and OCR technology, and through pixel range marking and JavaScript control, the automatic filling function of the test password manager is automatically generated to generate detailed test reports.

Benefits of technology

Improve testing efficiency, reduce manual operation time and cost, ensure the reliability and consistency of test results, avoid human factors, and ensure data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119415395B_ABST
    Figure CN119415395B_ABST
Patent Text Reader

Abstract

The present invention discloses a semi-automated testing method for the auto-fill function of a password manager, including: (1) A tester manually registers and logs in to a password manager account, and stores the login credentials of a Web site in the password manager; then manually tests the auto-fill function of the password manager, while marking the pixel range of the click position that triggers the rendering of the pop-up box and the pixel range of the click position that triggers the auto-fill operation; (2) Configure and start an end-to-end testing tool, then control the browser to access the Web site where the test case is located, and record the actual fill result according to the pixel range marked in step 1; (3) Compare the actual fill result with the expected fill result of the test case, verify whether the actual fill result fills the form of the Web site according to the expected fill result, and generate a test report. The present invention combines an automated method and end-to-end testing to achieve efficient testing of the auto-fill function of the password manager.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computers, and specifically to a semi - automated testing method for the automatic filling function of a password manager. Background Art

[0002] In modern Internet, Web - based websites have become the core platforms for Internet users to conduct various online interactions and activities, providing users with rich online services. To access these online services, users usually need to first create a website account. Subsequently, users can log in to the website and use the online services provided by the website. During the process of registering an account and logging in to the website, users must enter their personal information and login credentials (such as username and password) in the registration and login forms provided by the website.

[0003] A password manager is a tool to assist users in managing their login credentials, which usually provides services in the form of a browser - built - in module or a browser plugin. The main function of such tools is to securely store users' login credentials and be able to automatically fill in login forms, thus playing a significant role in enhancing user experience and operation efficiency. By automatically filling in the login forms provided by Web websites, the password manager greatly saves users' time. Therefore, automatic form filling has become the preferred method for users when filling in website forms. However, the automatic filling function may cause errors in certain situations. For example, on the pages of some Web websites, the password manager may not accurately identify each field of the login form, resulting in the password being incorrectly filled into the one - time authentication code or other inappropriate fields. These errors not only reduce the user experience but also introduce security risks. Therefore, it is particularly important to systematically test the automatic filling function of the password manager.

[0004] At present, the testing of the automatic filling function of the password manager mainly adopts the manual testing method. Testers are required to first log in to the password manager account, access the Web site, and trigger the automatic filling function of the password manager in the website form. After automatically filling the website form, the testers need to combine specific test cases and determine whether the password manager has filled the correct values into the appropriate website form fields through manual observation. For example, in the literature "Huaman N, Amft S, Oltrogge M, et al. They would do better if they worked together: The case of interaction problems between password managers and websites [C] / / 2021 IEEE Symposium on Security and Privacy (SP). IEEE, 2021: 1367-1381.", the researchers identified 39 problems with the automatic filling function of the password manager in website forms by analyzing user comments on browser plugins and the GitHub platform. The researchers constructed working examples for each problem and used manual testing to evaluate whether 15 password managers could correctly fill the information stored in the password manager into the website form in different working examples. To provide specific and intuitive evidence, the researchers recorded the testing process to enhance the credibility and reproducibility of the research conclusions. Generally speaking, the manual testing process is not only time-consuming, but also requires a large amount of human resources when faced with a large number of website forms to be tested and multiple password managers. In addition, the automatic filling function involves a large number of operation details. Due to the influence of human factors, the repeatability of testing is poor, and it is difficult to ensure the reliability of test results. In addition, relying on methods such as recording videos for verification also requires additional manpower and time.

[0005] In addition, in the field of Web site testing, End-to-End Testing (E2E) is a widely used method designed to verify the functionality and performance of an application. End-to-end testing simulates the operation behaviors of real users, covering all interaction links from the front-end user interface to the back-end server, ensuring that the application can operate normally in various usage scenarios. It allows testers to write automated scripts to simulate user operations on a Web site, such as clicking buttons, filling out website forms, and browsing website pages. However, traditional end-to-end testing tools are usually only used to test the Web site itself and do not involve browser plugins or other window handles of the current browser process (for example, the built-in password manager of the browser and the website page where the Web site is located are different window handles of the same browser process). However, the autofill function of the password manager often depends on new window handles generated by the browser or requires services provided by browser plugins.

[0006] Therefore, developing an automated testing method for the autofill function of the password manager to improve the efficiency of the autofill function and reduce the consumption of human resources is an urgent problem that researchers in this field need to solve. Summary of the Invention

[0007] Aiming at the deficiencies of the prior art, the technical problem to be solved by the present invention is to provide a semi-automated testing method for the autofill function of the password manager.

[0008] The technical solution of the present invention to solve the above technical problem is to provide a semi-automated testing method for the autofill function of the password manager, characterized in that the method includes the following steps:

[0009] Step 1, Initialization stage: The tester manually registers and logs in to the password manager account, stores the login credentials of the Web site in the password manager; then manually tests the autofill function of the password manager, while marking and recording the pixel range of the click position that triggers the rendering of the pop-up box; then the password manager renders a pop-up box, and then marks and records the pixel range of the click position that triggers the autofill operation;

[0010] Step 2, Automated testing stage: The tester configures and starts the end-to-end testing tool, starts the browser program, then controls the browser to access the Web site where the given test case is located, and according to the pixel range marked in Step 1, attempts to drive the password manager to fill the stored login credential data into the form of the Web site where the test case is located, and records the actual filling result;

[0011] Step 3, Result Comparison Phase: The tester compares the actual filling result in Step 2 with the expected filling result of the test case given in Step 2 to verify whether the actual filling result of the password manager fills the form of the Web site according to the expected filling result, and generates a test report.

[0012] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0013] (1) Through an innovative automated method, the present invention combines the ability to operate the browser in end-to-end testing. In particular, when the password manager plugin provides the auto-fill function, new DOM elements are added to the browser web page and can interact with the browser to generate responses (such as rendering a pop-up box), realizing the efficient testing of the auto-fill function of the password manager, reducing the time, cost of manual operations, and the influence of human factors on the test results, and ensuring the repeatability of the test and the reliability of the test results.

[0014] (2) The present invention can avoid the influence of human factors, ensure that the environmental conditions and configurations of each test are consistent, and improve the repeatability and consistency of the test results.

[0015] (3) Through script program control, the test data is only transmitted and used in the test environment, ensuring the security of the data.

[0016] (4) By combining OCR and JavaScript technologies, the present invention automatically extracts the filling result and compares it with the expected result to generate a detailed test report. Description of the Drawings

[0017] Figure 1 is the overall flowchart of the present invention;

[0018] Figure 2 is the pop-up box rendered by the password manager when the auto-fill function of the built-in password manager of Chrome browser is triggered in the present invention;

[0019] Figure 3 is the pop-up box rendered by 1Password after the auto-fill function of 1Password password manager is triggered in the present invention, which contains the information stored by the tester in the password manager and the icon of 1Password password manager;

[0020] Figure 4 is the flowchart of the password manager automatically filling the form after the auto-fill function of the password manager is triggered in the present invention. Detailed Embodiments

[0021] The following are specific embodiments of the present invention. The specific embodiments are only used to further illustrate the present invention in detail and do not limit the protection scope of the present invention.

[0022] The present invention provides a semi - automated testing method for the automatic filling function of a password manager (hereinafter referred to as the method), characterized in that the method comprises the following steps:

[0023] Step 1, Initialization stage: The tester manually registers and logs in to the password manager account, and stores the login credentials of the Web site in the password manager; then manually tests the automatic filling function of the password manager, while marking and recording the pixel range of the click position that triggers the rendering of the pop - up box; then the password manager renders a pop - up box, and then marks and records the pixel range of the click position that triggers the automatic filling operation.

[0024] Preferably, the specific steps of Step 1 are as follows:

[0025] Step 11, The tester manually registers and logs in to the password manager account, and then stores the login credentials corresponding to the form of the Web site in the password manager;

[0026] Preferably, in Step 11, the login credentials are the username and password registered by the tester on the Web site.

[0027] Preferably, in Step 11, the form is a standard Web login form that conforms to the OWASP and W3C standards, which includes input fields for the username and password and a submit button.

[0028] Preferably, in Step 11, the Web site is a website that conforms to the OWASP and W3C standards.

[0029] Step 12, The tester uses the login credentials stored in Step 11 to manually test the automatic filling function of the password manager: The tester first clicks on the first input box in the form of the Web site to trigger the automatic filling function of the password manager, while marking the pixel range of the click position when the automatic filling function is triggered and rendering the pop - up box; after clicking, the password manager renders a pop - up box, and in the pop - up box, the username and the masked - state password of the login credentials stored in Step 11 are identified (in this embodiment, as Figure 2 shown, it is the pop - up box rendered by the password manager built into the Chrome browser).

[0030] Preferably, in Step 12, the click position of the pop - up box is located at the password manager icon displayed at the end of the first input box of the Web site form (as Figure 3 shown, the end of this input box is the 1Password password manager icon), or at any point inside the input box.

[0031] Step 13. In the pop-up box rendered in Step 12, the tester manually marks the pixel range of the click position of the operation that triggers the password manager to automatically fill in the form of the Web site. When the tester clicks on any point within the pixel range, this click operation will trigger the password manager to fill the user login credential data stored in the password manager into the form of the Web site. (In this embodiment, as Figure 4 shown).

[0032] Step 2. Automated testing phase: The tester configures and starts the end-to-end testing tool, starts the browser program, then controls the browser to access the Web site where the given test case is located, and according to the pixel range marked in Step 1, tries to drive the password manager to fill the login credential data it stores into the form of the Web site where the test case is located, and records the actual filling result;

[0033] Preferably, the specific steps of Step 2 are as follows:

[0034] Step 21. The tester configures and starts the WebDriver of the end-to-end testing tool to generate a browser program, that is, opens the browser built into the end-to-end testing tool;

[0035] Preferably, in Step 21, when using the end-to-end testing tool to perform automated testing of the auto-fill function, the end-to-end testing tool is Selenium, Puppeteer or Playwright, preferably Selenium.

[0036] Preferably, in Step 21, when testing the password manager running as a browser plugin, the corresponding browser plugin needs to be additionally loaded when starting the browser.

[0037] Step 22. The tester controls the browser program generated in Step 21 by writing code to access the Web site where the target test form in the given test case is located, locates the form of the Web site of the test case, and clicks on any position within the pixel range obtained in Step 12, so that the password manager renders a pop-up box;

[0038] Preferably, in Step 22, in order to ensure that the web site can be loaded successfully, the end-to-end testing tool is used to refresh the page of this Web site once again.

[0039] Step 23. After the password manager renders the pop-up box, the tester operates the end-to-end testing tool to click on any position within the pixel range obtained in Step 13, and tries to drive the password manager to fill the user login credential data it stores into the form of the Web site where the test case is located; if in this attempt, the password manager does not fill in any information or does not render any pop-up box, then the tester uses the end-to-end testing tool to refresh the Web site and retry;

[0040] Step 24: When the tester successfully fills in the fields of the form of at least one web site in the password manager or fails to trigger the autofill function after no less than five attempts, obtain the actual filling result after the password manager uses the autofill function to fill in the form of the web site where the test case is located in this round of testing.

[0041] Preferably, in Step 24, the method for obtaining the actual filling result is a method combining JavaScript and OCR (Optical Character Recognition) technology: In the JavaScript-based method, the tester runs the code for obtaining the values of the fields in the form of the web site using an end-to-end testing tool, accesses the DOM nodes and obtains the data of the target form fields; when the JavaScript method is not applicable, that is, the form of the web site sets a specific protection mechanism that does not allow obtaining the filling data of the form through JavaScript, the tester takes a screenshot of the web site using an end-to-end testing tool and uses OCR technology to identify the actual filling result after triggering the autofill function of the password manager.

[0042] Step 3: Result comparison stage: The tester compares the actual filling result in Step 2 with the expected filling result of the test case given in Step 2, verifies whether the actual filling result of the password manager fills in the form of the web site according to the expected filling result, stores the comparison result in the database and generates a test report.

[0043] Preferably, in Step 3, the expected filling result is: The test case evaluates whether the password manager should fill in the login credentials in the form of the web site in the given test case according to the best practices of the security and usability of the password manager to obtain the expected filling result; where the best practices are security standards, industry standards, academic papers and national standards.

[0044] Preferably, the method further includes: Step 4: Test end stage: After the tester completes the test, closes the WebDriver of the end-to-end testing tool opened in Step 2 through a programming script, releases all relevant resources; clears the browser cache and all temporary data to ensure that all initialization data and environment configurations have been reset and ensure the consistency of the next test environment with the current round of test environment.

[0045] Where the present invention is not described shall be applicable to the prior art.

Claims

1. A semi - automated testing method for the automatic filling function of a password manager, characterized in that, The method includes the following steps: Step 1, initialization phase: Step 11, testers manually register and log in to the password manager account, and then store the login credentials corresponding to the form of the Web site in the password manager; Step 12, testers use the login credentials stored in Step 11 to manually test the autofill function of the password manager: testers first click on the first input box in the form of the Web site to trigger the autofill function of the password manager, and at the same time mark the pixel range of the click position where the pop-up box is rendered when the autofill function is triggered; after clicking, the password manager renders a pop-up box, and in the pop-up box, the user name and the masked password of the login credentials stored in Step 11 are identified; Step 13, in the pop-up box rendered in Step 12, testers manually mark the pixel range of the click position for the operation of triggering the password manager to autofill the form of the Web site; when testers click on any point within the pixel range, this click operation will trigger the password manager to fill the user login credential data stored in the password manager into the form of the Web site; Step 2, automated testing phase: Step 21, testers configure and start the end-to-end testing tool to generate a browser program; Step 22, testers control the browser program generated in Step 21 to access the Web site where the given test case is located, locate the form of the Web site of the test case, and click on any position within the pixel range obtained in Step 12 to make the password manager render a pop-up box; Step 23, after the password manager renders the pop-up box, testers operate the end-to-end testing tool to click on any position within the pixel range obtained in Step 13, and try to drive the password manager to fill the user login credential data it stores into the form of the Web site where the test case is located; if in this attempt, the password manager does not fill any information or does not render any pop-up box, then testers use the end-to-end testing tool to refresh the Web site and retry; Step 24, when testers have the password manager successfully fill at least one field of the form of the Web site or cannot trigger the autofill function after at least five attempts, obtain the actual filling result after the password manager uses the autofill function to fill the form of the Web site where the test case is located in this round of testing; Step 3, result comparison phase: testers compare the actual filling result in Step 2 with the expected filling result of the given test case in Step 2, verify whether the actual filling result of the password manager fills the form of the Web site according to the expected filling result, and generate a test report.

2. The semi-automated testing method for the automatic filling function of the password manager according to claim 1, characterized in that In Step 11, the login credentials are the user name and password registered by the tester on this Web site; The form is a standard Web login form that complies with OWASP and W3C standards, which includes input fields for the user name and password and a submit button.

3. The semi-automated test method for the automatic filling function of the password manager according to claim 1, characterized in that In Step 12, the click position of the pop-up box is located at the password manager icon displayed at the end of the first input box of the form of the Web site or at any point inside the input box.

4. The semi-automated testing method for the password manager's autofill function according to claim 1, characterized in that In step 21, when testing the password manager running as a browser plugin, the corresponding browser plugin needs to be additionally loaded when the browser is launched.

5. The semi-automated testing method for the password manager's auto-fill function according to claim 1, characterized in that In step 22, in order to ensure that the web site can be loaded successfully, use an end-to-end testing tool to refresh the page of the web site once again.

6. The semi-automated testing method for the password manager's auto-fill function according to claim 1, characterized in that, In step 24, the method for obtaining the actual filling result is a method combining JavaScript and OCR technologies: In the JavaScript-based method, testers use an end-to-end testing tool to run the code for obtaining the values of the fields in the form of the web site, access the DOM nodes and obtain the data of the target form fields; when the JavaScript method is not applicable, that is, the form of the web site sets a specific protection mechanism that does not allow obtaining the filled data of the form through JavaScript, testers take a screenshot of the web site using an end-to-end testing tool and use OCR technology to identify the actual filling result after triggering the automatic filling function of the password manager.

7. The semi-automated testing method for the password manager's autofill function according to claim 1, characterized in that, In step 3, the expected filling result is: The test case evaluates whether the password manager should fill in the login credentials into the form of the web site in the given test case according to the best practices of the security and usability of the password manager, and obtains the expected filling result; among which the best practices are security standards, industry standards, academic papers and national standards.

8. The semi-automated test method for the password manager's autofill function according to claim 1, characterized in that, This method further includes: Step 4, the test end stage: After the tester completes the test, close the end-to-end testing tool opened in step 2, release all relevant resources; clear the browser cache and all temporary data, ensure that all initialization data and environment configurations have been reset, and ensure the consistency of the next test environment with the current test environment.

Citation Information

Patent Citations

  • Page data acquisition method and device

    CN115438348A

  • Automatic testing method and device, electronic equipment and medium

    CN118672887A