113 lines
5.3 KiB
Markdown
113 lines
5.3 KiB
Markdown
# Google Play closed-test runbook
|
||
|
||
The developer account is a new personal account. Google currently requires at
|
||
least 12 testers to remain opted in to the closed test for 14 continuous days
|
||
before production access can be requested.
|
||
|
||
This requirement was rechecked against the official Play Console Help article
|
||
on 2026-08-25. The Console remains the source of truth for the account's actual
|
||
eligibility and the date on which production access can be requested.
|
||
|
||
## Before inviting testers
|
||
|
||
1. Complete Play developer identity and contact verification.
|
||
2. Create the Play app with package `org.whoneedhelp.mobile`.
|
||
3. Enable Play App Signing.
|
||
4. Record every signing-certificate fingerprint shown by Play, including all
|
||
identities shown for quantum-ready hybrid signing when present. Add every
|
||
applicable Play App Signing SHA-256 to production App Links and
|
||
Google/Firebase configuration, then verify the production association files.
|
||
5. Use the recorded production AAB already released only to Internal testing.
|
||
The current Internal release is `0.1.3 (4)` with SHA-256
|
||
`5147404e91aee6ef87014e19db93403fdb18a15e91b749737c494c372ea87371`;
|
||
its exact operator record is `internal-release-v4.md`.
|
||
6. Complete the store listing, App content, privacy, Data Safety, content rating,
|
||
ads, target-audience, and access declarations. Read-only Store settings
|
||
inspection on 2026-08-25 showed category **Social** and public contact email
|
||
`contact@whoneedhelp.com`; phone and website were empty.
|
||
7. Finish the internal test on the owner’s device, complete the foreground-
|
||
service declaration, then promote the verified build to the closed track.
|
||
As of 2026-08-25 the Internal release is active. The existing **Closed
|
||
testing - Alpha** track is inactive with zero of four setup tasks complete:
|
||
countries and testers are not selected, and the track has no release.
|
||
|
||
After installing from the internal-track opt-in link, verify the delivery
|
||
boundary before testing authenticated flows:
|
||
|
||
```bash
|
||
./scripts/verify-play-installed-android.sh \
|
||
/secure/downloads/play-identities.json \
|
||
DEVICE_SERIAL \
|
||
4 \
|
||
0.1.3
|
||
```
|
||
|
||
The verifier is read-only. It requires the Google Play installer, one of the
|
||
recorded Play App Signing SHA-256 identities, the exact expected version, and a
|
||
verified `whoneedhelp.com` App Link that resolves to `MainActivity`. A locally
|
||
sideloaded APK intentionally fails this gate even if its UI and package name
|
||
look correct.
|
||
|
||
## Tester cohort
|
||
|
||
- Recruit at least 12 real people with Google or Google Workspace accounts.
|
||
- Keep at least the required 12 testers continuously opted in for the complete
|
||
14-day interval. If anyone opts out, replace them if needed and use the date
|
||
shown by Play Console rather than assuming the original interval still
|
||
qualifies.
|
||
- Testers may join on different dates, but production access cannot be
|
||
requested until at least 12 currently opted-in testers have each satisfied
|
||
the continuous 14-day requirement shown by Play Console.
|
||
- Do not publish tester email addresses in the repository.
|
||
- Give every tester the Play opt-in link and state clearly that they must remain
|
||
opted in for at least 14 continuous days.
|
||
- Record opt-in date, device/Android version, completed scenarios, and feedback
|
||
in a private operational sheet.
|
||
|
||
Do not invent a larger required cohort or a shorter testing interval. The
|
||
current official minimum is 12 continuously opted-in testers for 14 days; Play
|
||
Console is the source of truth for whether the account has satisfied it.
|
||
|
||
## Required scenarios for each cohort
|
||
|
||
- Install and open from the Play closed-test listing.
|
||
- Register or sign in with Google/email.
|
||
- Review privacy and location controls.
|
||
- Create or browse a request without exposing an exact public address.
|
||
- Accept/withdraw from a safe test request using two separate accounts.
|
||
- Send and receive private messages and push notifications.
|
||
- Start and stop live location on a clearly labelled synthetic test assignment.
|
||
- Request to join and withdraw from an activity.
|
||
- Block/report a synthetic account and locate support/account deletion.
|
||
- Confirm that rotation, background/foreground, offline/reconnect, and process
|
||
recreation do not lose critical state.
|
||
|
||
Never ask testers to simulate a real emergency, disclose prescriptions or
|
||
medical details, exchange money, or travel to meet an unknown person.
|
||
|
||
## Feedback questions
|
||
|
||
1. What task did you try to complete?
|
||
2. At which screen did you hesitate or stop?
|
||
3. Was approximate versus exact location visibility understandable?
|
||
4. Did notifications arrive, and did they open the expected screen?
|
||
5. Could you tell when live location was active and stop it?
|
||
6. Did leaving a request/activity immediately update your participation state?
|
||
7. What device and Android version did you use?
|
||
8. Did you encounter a crash, blank screen, inaccessible control, or misleading
|
||
status?
|
||
|
||
## Evidence for production-access application
|
||
|
||
- Closed-track name and release/version code.
|
||
- Dates covering at least the required continuous 14-day interval.
|
||
- Opted-in tester count shown by Play Console.
|
||
- Device/Android coverage.
|
||
- Issues found, fixes made, and how fixes were re-tested.
|
||
- Summary of feedback and why the app is ready for production.
|
||
|
||
Official references:
|
||
|
||
- https://support.google.com/googleplay/android-developer/answer/14151465
|
||
- https://support.google.com/googleplay/android-developer/answer/9845334
|