Clarify support reply readiness boundary

This commit is contained in:
SimpleTest 2026-08-13 11:00:28 +03:00
parent 9aa371105f
commit 02ccebb5b9
3 changed files with 13 additions and 2 deletions

View File

@ -208,6 +208,13 @@ test checkout. The generated file uses the ordinary runtime names:
| Verified Android links | `ANDROID_APP_LINKS_PACKAGE_NAME`, `ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS` | | Verified Android links | `ANDROID_APP_LINKS_PACKAGE_NAME`, `ANDROID_APP_LINKS_SHA256_CERT_FINGERPRINTS` |
| Transactional email | `SMTP_*`, sender, and `SUPPORT_INBOX_ADDRESS` | | Transactional email | `SMTP_*`, sender, and `SUPPORT_INBOX_ADDRESS` |
`SUPPORT_INBOX_ADDRESS` configures `Reply-To` and the optional operator-alert
destination. The environment readiness script validates only that this value is
present and syntactically usable; it does not prove that the domain has inbound
MX routing or that the mailbox is monitored. Check DNS and perform an actual
inbound delivery/reply test before presenting the address as a public support
contact.
Do not reuse a Google client, VAPID private key, Firebase project/service Do not reuse a Google client, VAPID private key, Firebase project/service
account, SMTP credential, or Android signing key between dev and production. account, SMTP credential, or Android signing key between dev and production.
The public Firebase Android values are build configuration; the Base64 FCM The public Firebase Android values are build configuration; the Base64 FCM

View File

@ -67,6 +67,9 @@ The release check covers the application origin and secrets, database
selection, SMTP and support routing, Google OAuth, browser VAPID, Firebase/FCM, selection, SMTP and support routing, Google OAuth, browser VAPID, Firebase/FCM,
Android package/signing configuration, and production App Links. It does not Android package/signing configuration, and production App Links. It does not
prove that external providers will deliver successfully after deployment. prove that external providers will deliver successfully after deployment.
In particular, a configured `SUPPORT_INBOX_ADDRESS` is not evidence of inbound
mail delivery: verify its MX routing and complete a real receive-and-reply test
before using it in Google Play or public support pages.
## 3. Record human and legal decisions ## 3. Record human and legal decisions

View File

@ -226,9 +226,10 @@ else
fi fi
if is_set SUPPORT_INBOX_ADDRESS; then if is_set SUPPORT_INBOX_ADDRESS; then
ready "support inbox" "operator destination is configured" ready "support reply address" \
"address is configured; inbound DNS and mailbox delivery require a separate test"
else else
missing "support inbox" "SUPPORT_INBOX_ADDRESS" missing "support reply address" "SUPPORT_INBOX_ADDRESS"
fi fi
rate_limit_policies_json=$(value RATE_LIMIT_POLICIES_JSON) rate_limit_policies_json=$(value RATE_LIMIT_POLICIES_JSON)