62 lines
2.8 KiB
Markdown
62 lines
2.8 KiB
Markdown
# Google Play review access
|
||
|
||
The app has public pages, email/passwordless authentication, password
|
||
authentication, and Google sign-in.
|
||
Reviewers must be able to inspect restricted functionality without contacting a
|
||
real requester or sharing real personal/medical information.
|
||
|
||
## Recommended reviewer instructions
|
||
|
||
1. Open the app. The product home, Safety, Privacy, Terms, Support, content
|
||
reporting, and Account deletion pages are available without a reviewer
|
||
account. Request, activity, category-proposal, profile, notification, and
|
||
moderation LiveViews require authentication.
|
||
2. For authenticated functionality, use the dedicated production reviewer
|
||
account prepared immediately before submission.
|
||
3. Expand **Use a password instead**, then enter the dedicated reviewer email
|
||
and password supplied in Play Console. Do not use an email link or Google
|
||
sign-in for review: the supplied password must remain reusable, always
|
||
available, and independent of a developer mailbox or one-time code.
|
||
4. Use only the pre-created synthetic requests and activity. Their titles must
|
||
start with `Play review`.
|
||
5. A second synthetic account must already be assigned as the counterpart so the
|
||
reviewer can inspect chat, optional tracking controls, handover, withdrawal,
|
||
reviews, blocking, reporting, support, privacy, and account deletion.
|
||
|
||
## Submission-time values
|
||
|
||
Do not store credentials here or in Git. Put them only in Play Console’s app
|
||
access field:
|
||
|
||
- Reviewer email: create at release time.
|
||
- Reviewer password: create at release time and store only in Play Console and
|
||
the operator-controlled password manager.
|
||
- Stable synthetic request URL: create at release time.
|
||
- Stable synthetic activity URL: create at release time.
|
||
- Support contact: `contact@whoneedhelp.com`.
|
||
|
||
## Verification before submission
|
||
|
||
- Test the exact instructions in a clean Android install from the Play track.
|
||
- Confirm they do not depend on a developer browser session, VPN, localhost,
|
||
expiring fixture, or test/staging domain.
|
||
- Confirm the reviewer account is not a moderator or administrator.
|
||
- Confirm all data is synthetic and no real user can be messaged or located.
|
||
- Confirm the password works from a clean Play-delivered install without a
|
||
second factor, one-time code, developer browser session, or location gate.
|
||
|
||
After both dedicated accounts have registered, confirmed their email, and set
|
||
their fixed passwords through the production UI, an operator can create the
|
||
stable synthetic records from the production checkout:
|
||
|
||
```bash
|
||
./scripts/prepare-play-review.sh \
|
||
REVIEWER_EMAIL COUNTERPART_EMAIL \
|
||
--confirm whoneedhelp.com \
|
||
/srv/who_need_help-production/.env
|
||
```
|
||
|
||
The command does not create or change credentials. It refuses missing,
|
||
unconfirmed, suspended, passwordless, staff, or duplicate accounts and is
|
||
idempotent for its one request and one activity.
|