5.3 KiB
Google Play review access
The app has public pages, email/passwordless authentication, password authentication, and Google sign-in. Reviewers must be able to inspect restricted functionality without contacting a real requester or sharing real personal/medical information.
Recommended reviewer instructions
- Open the app. The product home, Safety, Privacy, Terms, Support, content reporting, and Account deletion pages are available without a reviewer account. Request, activity, category-proposal, profile, notification, and moderation LiveViews require authentication.
- For authenticated functionality, use the two dedicated production review accounts prepared immediately before submission. The requester/organizer account exposes one side of the flows; the helper/participant account exposes the other.
- Expand Use a password instead, then enter one of the dedicated emails and passwords supplied in Play Console. Do not use an email link or Google sign-in for review: both supplied passwords must remain reusable, always available, and independent of a developer mailbox or one-time code.
- Use only the pre-created synthetic requests and activity. Their titles must
start with
Play review. - Sign out and use the helper/participant credentials when checking acceptance, participant state, the counterpart chat view, optional tracking, handover, withdrawal, reviews, blocking, and reporting.
Submission-time values
Do not store credentials here or in Git. Put them only in Play Console’s app access field:
- Requester/organizer reviewer email and password: create at release time.
- Helper/participant reviewer email and password: create at release time.
- Store both credential pairs only in Play Console and the operator-controlled password manager.
- Stable synthetic request URL: create at release time.
- Stable synthetic activity URL: create at release time.
- Public support contact: choose at submission time only after the address has
passed a real inbound-delivery test.
contact@whoneedhelp.comis currently verified only as an outbound Brevo sender; DNS inspection found no MX record proving that replies or new inbound messages reach an operator.
Copy for Play Console App access
Use the following English instructions only after replacing all four bracketed values with the two dedicated production credential pairs and after testing the exact text from a clean Play-delivered installation. Never commit the completed version.
This app has public pages and authenticated product flows.
1. Open the app and tap Log in.
2. Expand "Use a password instead".
3. First enter the requester/organizer credentials below.
4. Open Requests and Activities to inspect the pre-created synthetic records,
requester/organizer controls, chat, location controls and reporting.
5. Sign out, return to Log in, expand "Use a password instead", and enter the
helper/participant credentials.
6. Open the same synthetic records to inspect the counterpart views, private
chat, acceptance/participation, tracking, handover, withdrawal, reviews,
blocking and reporting.
Requester/organizer email: [ENTER IN PLAY CONSOLE ONLY]
Requester/organizer password: [ENTER IN PLAY CONSOLE ONLY]
Helper/participant email: [ENTER IN PLAY CONSOLE ONLY]
Helper/participant password: [ENTER IN PLAY CONSOLE ONLY]
All records whose titles start with "Play review" are synthetic. No purchase,
payment, medicine, travel or real-world meeting is required. The credentials
are reusable, do not require a one-time code or developer mailbox, and work
independently of reviewer location.
Support: [ENTER A TESTED, MONITORED INBOUND ADDRESS IN PLAY CONSOLE ONLY]
After scripts/prepare-play-review.sh ... --confirm succeeds, append the exact
production request and activity URLs printed by the command. Do not use a dev,
test, localhost or expiring sign-in URL.
Verification before submission
- Test the exact instructions in a clean Android install from the Play track.
- Confirm they do not depend on a developer browser session, VPN, localhost, expiring fixture, or test/staging domain.
- Confirm neither review account has any staff role.
- Confirm all data is synthetic and no real user can be messaged or located.
- Confirm both passwords work from a clean Play-delivered install without a second factor, one-time code, developer browser session, or location gate.
- Confirm the final Play Console instructions are in English and every route they mention is reachable from the appropriate review account.
After both dedicated accounts have registered, confirmed their email, and set their fixed passwords through the production UI, first run the read-only readiness check from the production checkout:
./scripts/prepare-play-review.sh \
REVIEWER_EMAIL COUNTERPART_EMAIL \
--check-only whoneedhelp.com \
/srv/who_need_help-production/.env
Only after that check succeeds should an operator create the stable synthetic records:
./scripts/prepare-play-review.sh \
REVIEWER_EMAIL COUNTERPART_EMAIL \
--confirm whoneedhelp.com \
/srv/who_need_help-production/.env
The command does not create or change credentials. It refuses missing, unconfirmed, suspended, passwordless, staff, or duplicate accounts and is idempotent for its one request and one activity.