Cover both roles in Play review access

This commit is contained in:
SimpleTest 2026-08-03 23:31:32 +03:00
parent 95049b4a43
commit 1f0c271951
3 changed files with 41 additions and 32 deletions

View File

@ -50,7 +50,8 @@
- [ ] Privacy policy URL. - [ ] Privacy policy URL.
- [ ] Ads declaration: no ads. - [ ] Ads declaration: no ads.
- [ ] App access instructions tested from a clean install. - [ ] Both App access accounts and both sides of the reviewer instructions
tested from a clean Play-delivered install.
- [ ] Target audience/adult-only positioning confirmed. - [ ] Target audience/adult-only positioning confirmed.
- [ ] Content rating questionnaire completed truthfully. - [ ] Content rating questionnaire completed truthfully.
- [ ] Data Safety worksheet reconciled with the final dependency report. - [ ] Data Safety worksheet reconciled with the final dependency report.

View File

@ -11,34 +11,37 @@ real requester or sharing real personal/medical information.
reporting, and Account deletion pages are available without a reviewer reporting, and Account deletion pages are available without a reviewer
account. Request, activity, category-proposal, profile, notification, and account. Request, activity, category-proposal, profile, notification, and
moderation LiveViews require authentication. moderation LiveViews require authentication.
2. For authenticated functionality, use the dedicated production reviewer 2. For authenticated functionality, use the two dedicated production review
account prepared immediately before submission. accounts prepared immediately before submission. The requester/organizer
3. Expand **Use a password instead**, then enter the dedicated reviewer email account exposes one side of the flows; the helper/participant account exposes
and password supplied in Play Console. Do not use an email link or Google the other.
sign-in for review: the supplied password must remain reusable, always 3. Expand **Use a password instead**, then enter one of the dedicated emails and
available, and independent of a developer mailbox or one-time code. passwords supplied in Play Console. Do not use an email link or Google sign-in
for review: both supplied passwords must remain reusable, always available,
and independent of a developer mailbox or one-time code.
4. Use only the pre-created synthetic requests and activity. Their titles must 4. Use only the pre-created synthetic requests and activity. Their titles must
start with `Play review`. start with `Play review`.
5. A second synthetic account must already be assigned as the counterpart so the 5. Sign out and use the helper/participant credentials when checking acceptance,
reviewer can inspect chat, optional tracking controls, handover, withdrawal, participant state, the counterpart chat view, optional tracking, handover,
reviews, blocking, reporting, support, privacy, and account deletion. withdrawal, reviews, blocking, and reporting.
## Submission-time values ## Submission-time values
Do not store credentials here or in Git. Put them only in Play Console’s app Do not store credentials here or in Git. Put them only in Play Console’s app
access field: access field:
- Reviewer email: create at release time. - Requester/organizer reviewer email and password: create at release time.
- Reviewer password: create at release time and store only in Play Console and - Helper/participant reviewer email and password: create at release time.
the operator-controlled password manager. - Store both credential pairs only in Play Console and the operator-controlled
password manager.
- Stable synthetic request URL: create at release time. - Stable synthetic request URL: create at release time.
- Stable synthetic activity URL: create at release time. - Stable synthetic activity URL: create at release time.
- Support contact: `contact@whoneedhelp.com`. - Support contact: `contact@whoneedhelp.com`.
## Copy for Play Console App access ## Copy for Play Console App access
Use the following English instructions only after replacing both bracketed Use the following English instructions only after replacing all four bracketed
values with the dedicated production reviewer credentials and after testing the values with the two dedicated production credential pairs and after testing the
exact text from a clean Play-delivered installation. Never commit the completed exact text from a clean Play-delivered installation. Never commit the completed
version. version.
@ -47,14 +50,19 @@ This app has public pages and authenticated product flows.
1. Open the app and tap Log in. 1. Open the app and tap Log in.
2. Expand "Use a password instead". 2. Expand "Use a password instead".
3. Enter the reusable reviewer credentials below. 3. First enter the requester/organizer credentials below.
4. After signing in, open Requests to inspect the pre-created synthetic help 4. Open Requests and Activities to inspect the pre-created synthetic records,
request and its private chat, location controls, handover and reporting. requester/organizer controls, chat, location controls and reporting.
5. Open Activities to inspect the pre-created synthetic cinema activity and 5. Sign out, return to Log in, expand "Use a password instead", and enter the
participation controls. helper/participant credentials.
6. Open the same synthetic records to inspect the counterpart views, private
chat, acceptance/participation, tracking, handover, withdrawal, reviews,
blocking and reporting.
Reviewer email: [ENTER IN PLAY CONSOLE ONLY] Requester/organizer email: [ENTER IN PLAY CONSOLE ONLY]
Reviewer password: [ENTER IN PLAY CONSOLE ONLY] Requester/organizer password: [ENTER IN PLAY CONSOLE ONLY]
Helper/participant email: [ENTER IN PLAY CONSOLE ONLY]
Helper/participant password: [ENTER IN PLAY CONSOLE ONLY]
All records whose titles start with "Play review" are synthetic. No purchase, All records whose titles start with "Play review" are synthetic. No purchase,
payment, medicine, travel or real-world meeting is required. The credentials payment, medicine, travel or real-world meeting is required. The credentials
@ -73,12 +81,12 @@ test, localhost or expiring sign-in URL.
- Test the exact instructions in a clean Android install from the Play track. - Test the exact instructions in a clean Android install from the Play track.
- Confirm they do not depend on a developer browser session, VPN, localhost, - Confirm they do not depend on a developer browser session, VPN, localhost,
expiring fixture, or test/staging domain. expiring fixture, or test/staging domain.
- Confirm the reviewer account is not a moderator or administrator. - Confirm neither review account has any staff role.
- Confirm all data is synthetic and no real user can be messaged or located. - Confirm all data is synthetic and no real user can be messaged or located.
- Confirm the password works from a clean Play-delivered install without a - Confirm both passwords work from a clean Play-delivered install without a
second factor, one-time code, developer browser session, or location gate. second factor, one-time code, developer browser session, or location gate.
- Confirm the final Play Console instructions are in English and every route - Confirm the final Play Console instructions are in English and every route
they mention is reachable by the reviewer account. they mention is reachable from the appropriate review account.
After both dedicated accounts have registered, confirmed their email, and set After both dedicated accounts have registered, confirmed their email, and set
their fixed passwords through the production UI, first run the read-only their fixed passwords through the production UI, first run the read-only

View File

@ -44,13 +44,13 @@ require Play Console. It contains no account credentials or signing keys.
## Required before Play review ## Required before Play review
- Create a dedicated non-staff production reviewer account with a fixed, - Register and confirm two dedicated non-staff production review accounts with
reusable password. Put its credentials only in Play Console App access and fixed, reusable passwords: one requester/organizer and one
the operator-controlled password manager. helper/participant. Put both credential pairs only in Play Console App access
- Register and confirm two dedicated non-staff accounts with fixed passwords, and the operator-controlled password manager.
then create their stable synthetic `Play review` request and activity using - Create their stable synthetic `Play review` request and activity using
`scripts/prepare-play-review.sh`. Verify every reviewer instruction from a `scripts/prepare-play-review.sh`. Verify both roles and every reviewer
clean installation. instruction from a clean Play-delivered installation.
- Complete App content: App access, Ads, Content rating, Target audience, - Complete App content: App access, Ads, Content rating, Target audience,
News-app declaration, Data Safety, background-location declaration if Play News-app declaration, Data Safety, background-location declaration if Play
presents it, and the account-deletion URL. presents it, and the account-deletion URL.