118 lines
5.3 KiB
Markdown
118 lines
5.3 KiB
Markdown
# Google Play review access
|
||
|
||
The app has public pages, email/passwordless authentication, password
|
||
authentication, and Google sign-in.
|
||
Reviewers must be able to inspect restricted functionality without contacting a
|
||
real requester or sharing real personal/medical information.
|
||
|
||
## Recommended reviewer instructions
|
||
|
||
1. Open the app. The product home, Safety, Privacy, Terms, Support, content
|
||
reporting, and Account deletion pages are available without a reviewer
|
||
account. Request, activity, category-proposal, profile, notification, and
|
||
moderation LiveViews require authentication.
|
||
2. For authenticated functionality, use the two dedicated production review
|
||
accounts prepared immediately before submission. The requester/organizer
|
||
account exposes one side of the flows; the helper/participant account exposes
|
||
the other.
|
||
3. Expand **Use a password instead**, then enter one of the dedicated emails and
|
||
passwords supplied in Play Console. Do not use an email link or Google sign-in
|
||
for review: both supplied passwords must remain reusable, always available,
|
||
and independent of a developer mailbox or one-time code.
|
||
4. Use only the pre-created synthetic requests and activity. Their titles must
|
||
start with `Play review`.
|
||
5. Sign out and use the helper/participant credentials when checking acceptance,
|
||
participant state, the counterpart chat view, optional tracking, handover,
|
||
withdrawal, reviews, blocking, and reporting.
|
||
|
||
## Submission-time values
|
||
|
||
Do not store credentials here or in Git. Put them only in Play Console’s app
|
||
access field:
|
||
|
||
- Requester/organizer reviewer email and password: create at release time.
|
||
- Helper/participant reviewer email and password: create at release time.
|
||
- Store both credential pairs only in Play Console and the operator-controlled
|
||
password manager.
|
||
- Stable synthetic request URL: create at release time.
|
||
- Stable synthetic activity URL: create at release time.
|
||
- Public support contact: choose at submission time only after the address has
|
||
passed a real inbound-delivery test. `contact@whoneedhelp.com` is currently
|
||
verified only as an outbound Brevo sender; DNS inspection found no MX record
|
||
proving that replies or new inbound messages reach an operator.
|
||
|
||
## Copy for Play Console App access
|
||
|
||
Use the following English instructions only after replacing all four bracketed
|
||
values with the two dedicated production credential pairs and after testing the
|
||
exact text from a clean Play-delivered installation. Never commit the completed
|
||
version.
|
||
|
||
```text
|
||
This app has public pages and authenticated product flows.
|
||
|
||
1. Open the app and tap Log in.
|
||
2. Expand "Use a password instead".
|
||
3. First enter the requester/organizer credentials below.
|
||
4. Open Requests and Activities to inspect the pre-created synthetic records,
|
||
requester/organizer controls, chat, location controls and reporting.
|
||
5. Sign out, return to Log in, expand "Use a password instead", and enter the
|
||
helper/participant credentials.
|
||
6. Open the same synthetic records to inspect the counterpart views, private
|
||
chat, acceptance/participation, tracking, handover, withdrawal, reviews,
|
||
blocking and reporting.
|
||
|
||
Requester/organizer email: [ENTER IN PLAY CONSOLE ONLY]
|
||
Requester/organizer password: [ENTER IN PLAY CONSOLE ONLY]
|
||
Helper/participant email: [ENTER IN PLAY CONSOLE ONLY]
|
||
Helper/participant password: [ENTER IN PLAY CONSOLE ONLY]
|
||
|
||
All records whose titles start with "Play review" are synthetic. No purchase,
|
||
payment, medicine, travel or real-world meeting is required. The credentials
|
||
are reusable, do not require a one-time code or developer mailbox, and work
|
||
independently of reviewer location.
|
||
|
||
Support: [ENTER A TESTED, MONITORED INBOUND ADDRESS IN PLAY CONSOLE ONLY]
|
||
```
|
||
|
||
After `scripts/prepare-play-review.sh ... --confirm` succeeds, append the exact
|
||
production request and activity URLs printed by the command. Do not use a dev,
|
||
test, localhost or expiring sign-in URL.
|
||
|
||
## Verification before submission
|
||
|
||
- Test the exact instructions in a clean Android install from the Play track.
|
||
- Confirm they do not depend on a developer browser session, VPN, localhost,
|
||
expiring fixture, or test/staging domain.
|
||
- Confirm neither review account has any staff role.
|
||
- Confirm all data is synthetic and no real user can be messaged or located.
|
||
- Confirm both passwords work from a clean Play-delivered install without a
|
||
second factor, one-time code, developer browser session, or location gate.
|
||
- Confirm the final Play Console instructions are in English and every route
|
||
they mention is reachable from the appropriate review account.
|
||
|
||
After both dedicated accounts have registered, confirmed their email, and set
|
||
their fixed passwords through the production UI, first run the read-only
|
||
readiness check from the production checkout:
|
||
|
||
```bash
|
||
./scripts/prepare-play-review.sh \
|
||
REVIEWER_EMAIL COUNTERPART_EMAIL \
|
||
--check-only whoneedhelp.com \
|
||
/srv/who_need_help-production/.env
|
||
```
|
||
|
||
Only after that check succeeds should an operator create the stable synthetic
|
||
records:
|
||
|
||
```bash
|
||
./scripts/prepare-play-review.sh \
|
||
REVIEWER_EMAIL COUNTERPART_EMAIL \
|
||
--confirm whoneedhelp.com \
|
||
/srv/who_need_help-production/.env
|
||
```
|
||
|
||
The command does not create or change credentials. It refuses missing,
|
||
unconfirmed, suspended, passwordless, staff, or duplicate accounts and is
|
||
idempotent for its one request and one activity.
|