107 lines
4.5 KiB
Markdown
107 lines
4.5 KiB
Markdown
# Google Play review access
|
||
|
||
The app has public pages, email/passwordless authentication, password
|
||
authentication, and Google sign-in.
|
||
Reviewers must be able to inspect restricted functionality without contacting a
|
||
real requester or sharing real personal/medical information.
|
||
|
||
## Recommended reviewer instructions
|
||
|
||
1. Open the app. The product home, Safety, Privacy, Terms, Support, content
|
||
reporting, and Account deletion pages are available without a reviewer
|
||
account. Request, activity, category-proposal, profile, notification, and
|
||
moderation LiveViews require authentication.
|
||
2. For authenticated functionality, use the dedicated production reviewer
|
||
account prepared immediately before submission.
|
||
3. Expand **Use a password instead**, then enter the dedicated reviewer email
|
||
and password supplied in Play Console. Do not use an email link or Google
|
||
sign-in for review: the supplied password must remain reusable, always
|
||
available, and independent of a developer mailbox or one-time code.
|
||
4. Use only the pre-created synthetic requests and activity. Their titles must
|
||
start with `Play review`.
|
||
5. A second synthetic account must already be assigned as the counterpart so the
|
||
reviewer can inspect chat, optional tracking controls, handover, withdrawal,
|
||
reviews, blocking, reporting, support, privacy, and account deletion.
|
||
|
||
## Submission-time values
|
||
|
||
Do not store credentials here or in Git. Put them only in Play Console’s app
|
||
access field:
|
||
|
||
- Reviewer email: create at release time.
|
||
- Reviewer password: create at release time and store only in Play Console and
|
||
the operator-controlled password manager.
|
||
- Stable synthetic request URL: create at release time.
|
||
- Stable synthetic activity URL: create at release time.
|
||
- Support contact: `contact@whoneedhelp.com`.
|
||
|
||
## Copy for Play Console App access
|
||
|
||
Use the following English instructions only after replacing both bracketed
|
||
values with the dedicated production reviewer credentials and after testing the
|
||
exact text from a clean Play-delivered installation. Never commit the completed
|
||
version.
|
||
|
||
```text
|
||
This app has public pages and authenticated product flows.
|
||
|
||
1. Open the app and tap Log in.
|
||
2. Expand "Use a password instead".
|
||
3. Enter the reusable reviewer credentials below.
|
||
4. After signing in, open Requests to inspect the pre-created synthetic help
|
||
request and its private chat, location controls, handover and reporting.
|
||
5. Open Activities to inspect the pre-created synthetic cinema activity and
|
||
participation controls.
|
||
|
||
Reviewer email: [ENTER IN PLAY CONSOLE ONLY]
|
||
Reviewer password: [ENTER IN PLAY CONSOLE ONLY]
|
||
|
||
All records whose titles start with "Play review" are synthetic. No purchase,
|
||
payment, medicine, travel or real-world meeting is required. The credentials
|
||
are reusable, do not require a one-time code or developer mailbox, and work
|
||
independently of reviewer location.
|
||
|
||
Support: contact@whoneedhelp.com
|
||
```
|
||
|
||
After `scripts/prepare-play-review.sh ... --confirm` succeeds, append the exact
|
||
production request and activity URLs printed by the command. Do not use a dev,
|
||
test, localhost or expiring sign-in URL.
|
||
|
||
## Verification before submission
|
||
|
||
- Test the exact instructions in a clean Android install from the Play track.
|
||
- Confirm they do not depend on a developer browser session, VPN, localhost,
|
||
expiring fixture, or test/staging domain.
|
||
- Confirm the reviewer account is not a moderator or administrator.
|
||
- Confirm all data is synthetic and no real user can be messaged or located.
|
||
- Confirm the password works from a clean Play-delivered install without a
|
||
second factor, one-time code, developer browser session, or location gate.
|
||
- Confirm the final Play Console instructions are in English and every route
|
||
they mention is reachable by the reviewer account.
|
||
|
||
After both dedicated accounts have registered, confirmed their email, and set
|
||
their fixed passwords through the production UI, first run the read-only
|
||
readiness check from the production checkout:
|
||
|
||
```bash
|
||
./scripts/prepare-play-review.sh \
|
||
REVIEWER_EMAIL COUNTERPART_EMAIL \
|
||
--check-only whoneedhelp.com \
|
||
/srv/who_need_help-production/.env
|
||
```
|
||
|
||
Only after that check succeeds should an operator create the stable synthetic
|
||
records:
|
||
|
||
```bash
|
||
./scripts/prepare-play-review.sh \
|
||
REVIEWER_EMAIL COUNTERPART_EMAIL \
|
||
--confirm whoneedhelp.com \
|
||
/srv/who_need_help-production/.env
|
||
```
|
||
|
||
The command does not create or change credentials. It refuses missing,
|
||
unconfirmed, suspended, passwordless, staff, or duplicate accounts and is
|
||
idempotent for its one request and one activity.
|