who_need_help/android/play-store/review-access.md

47 lines
2.3 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Google Play review access
The app has public pages, email/passwordless authentication, password
authentication, and Google sign-in.
Reviewers must be able to inspect restricted functionality without contacting a
real requester or sharing real personal/medical information.
## Recommended reviewer instructions
1. Open the app. The product home, Safety, Privacy, Terms, Support, content
reporting, and Account deletion pages are available without a reviewer
account. Request, activity, category-proposal, profile, notification, and
moderation LiveViews require authentication.
2. For authenticated functionality, use the dedicated production reviewer
account prepared immediately before submission.
3. Expand **Use a password instead**, then enter the dedicated reviewer email
and password supplied in Play Console. Do not use an email link or Google
sign-in for review: the supplied password must remain reusable, always
available, and independent of a developer mailbox or one-time code.
4. Use only the pre-created synthetic requests and activity. Their titles must
start with `Play review`.
5. A second synthetic account must already be assigned as the counterpart so the
reviewer can inspect chat, optional tracking controls, handover, withdrawal,
reviews, blocking, reporting, support, privacy, and account deletion.
## Submission-time values
Do not store credentials here or in Git. Put them only in Play Console’s app
access field:
- Reviewer email: create at release time.
- Reviewer password: create at release time and store only in Play Console and
the operator-controlled password manager.
- Stable synthetic request URL: create at release time.
- Stable synthetic activity URL: create at release time.
- Support contact: `contact@whoneedhelp.com`.
## Verification before submission
- Test the exact instructions in a clean Android install from the Play track.
- Confirm they do not depend on a developer browser session, VPN, localhost,
expiring fixture, or test/staging domain.
- Confirm the reviewer account is not a moderator or administrator.
- Confirm all data is synthetic and no real user can be messaged or located.
- Confirm the password works from a clean Play-delivered install without a
second factor, one-time code, developer browser session, or location gate.