No developer payload when purchasing using promo code within app or through 
play store.

Developer payload is the main defence against fake purchases. (As suggested 
by Google guy@netomarin <https://github.com/netomarin> here 
https://www.youtube.com/watch?v=tRpGcA4IM5Q)


Now that purchases using promo code do not return developer payload even if 
the purchase is initiated within app, there is no defence against fake 
purchases.


Developer payload should be returned irrespective of payment method (credit 
card or promo code). If the redeeming of promo code happens through play 
store, we could be asked to provide static developer payload through 
developer console. So it is easy for google play to provide developer 
payload in any scenario.


Google, Are you working on this critical issue?

On Wednesday, March 9, 2016 at 2:38:16 PM UTC+5:30, Jérémy R wrote:
>
> Hi all,
>
> We are several developers to experience issue with in-app purchases & 
> promotion: if the promotion is used inside the app instead of the standard 
> payment method, the returned developer payload is empty.
> A post has been opened on Stack Overflow: 
> http://stackoverflow.com/questions/34979420/in-app-purchases-made-via-promo-codes-return-empty-developer-payload-string
>
> I asked the Google Play Developer Support (googleplay-dev...@google.com 
> <javascript:>) but the answer I received is globally "there is no bug".
>
> Moreover, as commented in a comment by user greywolf82, when you use the 
> promotion via the Google Play store, this purchase can't have a developer 
> payload so it may be a serious security flaw if we can't check the 
> developer payload validity.
>
> So, does anyone have a valid developer payload after using a promotion 
> code?
>  
>

-- 
You received this message because you are subscribed to the Google Groups 
"Android Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to android-developers+unsubscr...@googlegroups.com.
To post to this group, send email to android-developers@googlegroups.com.
Visit this group at https://groups.google.com/group/android-developers.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/android-developers/a2dc7b6d-b405-4575-87e4-ea4583b1b6f8%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to