Does a successful login prove that the password was known?¶
No. Successful access may use a session token, security key, certificate, biometric, stored credential or single sign-on. The success result must be tied to an authentication method before it can say anything about a password.
Many routes require no password entry at that moment¶
Browsers and applications routinely reuse cookies and refresh tokens. A trusted device may unlock a stored secret, and federated sign-in can rely on another provider. Someone using an unlocked or remotely controlled device may never see the password.
Even an event confirming password authentication proves that the correct secret was supplied. It does not necessarily show that the controller memorised or manually typed it; software could store it or remote input could supply it.
Test the precise proposition¶
Obtain the provider's method field and determine whether the event was primary authentication, session continuation, token refresh or step-up verification. Multi-factor, device, token and account-recovery records can clarify the route.
If the issue is personal knowledge of the password, supporting communications, credential storage or disclosure evidence may be needed. Describe the accepted method rather than upgrading a generic success label into proof of knowledge.
The point to remember
Successful access proves only the authentication method the records actually identify - not automatic password knowledge.