who_need_help/docs/google-play-pre-upload-audit-2026-08-03.md

81 lines
4.3 KiB
Markdown

# Google Play pre-upload audit — 2026-08-03
This audit separates verified repository/device facts from actions that still
require Play Console. It contains no account credentials or signing keys.
## Verified locally
- The selected upload artifact and its checksum are recorded in
`docs/google-play-release-candidate-2026-08-03.md`.
- Package `org.whoneedhelp.mobile`, version code `1`, version name `0.1.0`,
minimum SDK `24`, and target SDK `37` were verified from the release build.
- Release unit tests, lint, R8, signing verification, and bundletool validation
passed. The release lint report contains no errors or warnings.
- The native disclosure appears before the location permission flow and
explicitly describes precise-location collection and transmission,
background use while minimized or not in use, persistent notification,
stopping, raw-location deletion, and retained summary evidence.
- English, Russian, and Ukrainian disclosure and store-listing text describe
the same behavior.
- The public Privacy page identifies Firebase Cloud Messaging and Firebase
Installations, the current OpenStreetMap Foundation tile service, and the
Android foreground location service behavior.
- Public Privacy, Terms, Safety, Support, content-reporting, and account-deletion
routes exist in the product. Reviewer guidance is recorded in
`android/play-store/review-access.md`.
- The release APK was installed on the authorised Android 16 physical device.
The production home and Safety pages rendered, the production App Link opened
`MainActivity`, and Android reported `whoneedhelp.com` as verified.
- The clean PID-scoped application log contains no application crash,
AndroidRuntime, TLS/SSL, or WebView load error.
- No analytics SDK is declared as active in the Android application. Data Safety
answers must still describe the behavior of Firebase Messaging/Installations
and the app's own server communication.
## Verified Play Console state
- The personal developer identity and contact phone are verified.
- The Play application exists as app ID `4972430103169452589`, package
`org.whoneedhelp.mobile`; it is a free app, not a game, with no ads.
- Play App Signing was accepted.
- The exact version-code `1` release AAB is retained in an internal-testing
draft. The internal release is not yet available to testers, so its
Play-generated signing identity and Play-delivered behavior remain unknown.
## Required before Play review
- Create a dedicated non-staff production reviewer account with a fixed,
reusable password. Put its credentials only in Play Console App access and
the operator-controlled password manager.
- Register and confirm two dedicated non-staff accounts with fixed passwords,
then create their stable synthetic `Play review` request and activity using
`scripts/prepare-play-review.sh`. Verify every reviewer instruction from a
clean installation.
- Complete App content: App access, Ads, Content rating, Target audience,
News-app declaration, Data Safety, background-location declaration if Play
presents it, and the account-deletion URL.
- Recheck the store listing, screenshots, support contact, and privacy-policy
URL in Play Console against the prepared files under `android/play-store/`.
## Required immediately after the internal release is accepted
- Record the Google Play App Signing SHA-1 and SHA-256. These are different from
the upload-certificate fingerprints documented for the local artifact.
- Add the Play App Signing fingerprints to the production Firebase Android app
and production App Links association, then recheck domain verification.
- Install the Play-delivered build from the internal-testing opt-in link and
repeat production-origin, sign-in, push-notification, foreground/background
location, stop-sharing, and App Link smoke tests.
- Only after the Play-delivered build passes, prepare the closed test with at
least 12 continuously opted-in testers for at least 14 days before requesting
production access.
## Scope protection
- Do not upload an older candidate or rebuild after choosing the upload AAB
without recording a new source fingerprint and SHA-256.
- Do not put reviewer passwords, service-account JSON, signing keys, `.env`
files, or Play Console tokens in Git.
- Do not update or restart the frozen hackathon test project as part of the Play
release workflow.