who_need_help/android/play-store/review-access.md

3.0 KiB
Raw Blame History

Google Play review access

The app has public pages, email/passwordless authentication, password authentication, and Google sign-in. Reviewers must be able to inspect restricted functionality without contacting a real requester or sharing real personal/medical information.

  1. Open the app. The product home, Safety, Privacy, Terms, Support, content reporting, and Account deletion pages are available without a reviewer account. Request, activity, category-proposal, profile, notification, and moderation LiveViews require authentication.
  2. For authenticated functionality, use the dedicated production reviewer account prepared immediately before submission.
  3. Expand Use a password instead, then enter the dedicated reviewer email and password supplied in Play Console. Do not use an email link or Google sign-in for review: the supplied password must remain reusable, always available, and independent of a developer mailbox or one-time code.
  4. Use only the pre-created synthetic requests and activity. Their titles must start with Play review.
  5. A second synthetic account must already be assigned as the counterpart so the reviewer can inspect chat, optional tracking controls, handover, withdrawal, reviews, blocking, reporting, support, privacy, and account deletion.

Submission-time values

Do not store credentials here or in Git. Put them only in Play Console’s app access field:

  • Reviewer email: create at release time.
  • Reviewer password: create at release time and store only in Play Console and the operator-controlled password manager.
  • Stable synthetic request URL: create at release time.
  • Stable synthetic activity URL: create at release time.
  • Support contact: contact@whoneedhelp.com.

Verification before submission

  • Test the exact instructions in a clean Android install from the Play track.
  • Confirm they do not depend on a developer browser session, VPN, localhost, expiring fixture, or test/staging domain.
  • Confirm the reviewer account is not a moderator or administrator.
  • Confirm all data is synthetic and no real user can be messaged or located.
  • Confirm the password works from a clean Play-delivered install without a second factor, one-time code, developer browser session, or location gate.

After both dedicated accounts have registered, confirmed their email, and set their fixed passwords through the production UI, first run the read-only readiness check from the production checkout:

./scripts/prepare-play-review.sh \
  REVIEWER_EMAIL COUNTERPART_EMAIL \
  --check-only whoneedhelp.com \
  /srv/who_need_help-production/.env

Only after that check succeeds should an operator create the stable synthetic records:

./scripts/prepare-play-review.sh \
  REVIEWER_EMAIL COUNTERPART_EMAIL \
  --confirm whoneedhelp.com \
  /srv/who_need_help-production/.env

The command does not create or change credentials. It refuses missing, unconfirmed, suspended, passwordless, staff, or duplicate accounts and is idempotent for its one request and one activity.