diff --git a/android/play-store/release-checklist.md b/android/play-store/release-checklist.md index 1d37349..2ba67f2 100644 --- a/android/play-store/release-checklist.md +++ b/android/play-store/release-checklist.md @@ -13,10 +13,10 @@ - [x] Default language: English (United States). - [x] App: not a game; free; no ads. - [x] Accept Play App Signing. -- [ ] Record upload-certificate SHA-256 and Play App Signing SHA-256 separately. - The source-bound candidate records the upload SHA-256; the Play App - Signing SHA-256 remains pending until the first internal release is - accepted by Play Console. +- [x] Record the upload-certificate SHA-1 and SHA-256 with the source-bound + candidate. +- [ ] Record the distinct Play App Signing SHA-1 and SHA-256 after Play accepts + the first internal release. - [ ] Add the Play App Signing SHA-256 to production Google/Firebase Android configuration. - [ ] Publish and verify diff --git a/docs/google-play-pre-upload-audit-2026-08-03.md b/docs/google-play-pre-upload-audit-2026-08-03.md index b00492c..07212b3 100644 --- a/docs/google-play-pre-upload-audit-2026-08-03.md +++ b/docs/google-play-pre-upload-audit-2026-08-03.md @@ -32,12 +32,18 @@ require Play Console. It contains no account credentials or signing keys. answers must still describe the behavior of Firebase Messaging/Installations and the app's own server communication. -## Required before the first upload +## Verified Play Console state + +- The personal developer identity and contact phone are verified. +- The Play application exists as app ID `4972430103169452589`, package + `org.whoneedhelp.mobile`; it is a free app, not a game, with no ads. +- Play App Signing was accepted. +- The exact version-code `1` release AAB is retained in an internal-testing + draft. The internal release is not yet available to testers, so its + Play-generated signing identity and Play-delivered behavior remain unknown. + +## Required before Play review -- Create the Play Console app if it does not yet exist. This state is not - confirmed by repository or device evidence. -- Deploy the current Privacy-page changes to production before submitting the - app for review. Do not change the frozen hackathon test deployment. - Create a dedicated non-staff production reviewer account with a fixed, reusable password. Put its credentials only in Play Console App access and the operator-controlled password manager. @@ -51,7 +57,7 @@ require Play Console. It contains no account credentials or signing keys. - Recheck the store listing, screenshots, support contact, and privacy-policy URL in Play Console against the prepared files under `android/play-store/`. -## Required immediately after the first upload +## Required immediately after the internal release is accepted - Record the Google Play App Signing SHA-1 and SHA-256. These are different from the upload-certificate fingerprints documented for the local artifact. diff --git a/docs/google-play-release-candidate-2026-08-03.md b/docs/google-play-release-candidate-2026-08-03.md index 275aba7..0bb0483 100644 --- a/docs/google-play-release-candidate-2026-08-03.md +++ b/docs/google-play-release-candidate-2026-08-03.md @@ -71,22 +71,26 @@ App Links association. observability, and image-security gates. - The final runtime image scan reported zero detected vulnerabilities. -## First Play Console session +## Current Play Console state -1. Create **Who Need Help** as an app (not a game), free, default language - English (United States), support email `contact@whoneedhelp.com`. -2. Accept the policy, export-law, and Play App Signing declarations. +The verified personal developer account contains the Who Need Help application +with Play application ID `4972430103169452589`. Play App Signing was accepted. +The internal-testing draft contains the exact version-code `1` AAB identified +above, but the release has not yet been saved/published to testers. A failed +duplicate-upload row must not be confused with the accepted artifact. + +The remaining Console sequence is: + +1. Keep the accepted version-code `1` artifact and remove only the failed + duplicate-upload row from the draft. +2. Save/publish the internal release and obtain the Play App Signing SHA-1 and + SHA-256 from **Test and release → Setup → App signing**. 3. Complete the prepared store listing and App content sections using `android/play-store/` and `android/store-assets/`. -4. Upload only the AAB identified above to an internal-testing release first. - The older `android/dist-release-20260803-183258/` candidate is superseded and - must not be uploaded. -5. Install the Play-delivered build from the internal-test opt-in link and +4. Install the Play-delivered build from the internal-test opt-in link and repeat the production-origin, sign-in, notification, location, and App Link smoke tests. -6. Record the Play App Signing SHA-1 and SHA-256 before starting the closed - test. -7. Start a closed test with at least 12 continuously opted-in testers for at +5. Start a closed test with at least 12 continuously opted-in testers for at least 14 days before requesting production access. Official references: