No developer payload when purchasing using promo code within app or through play store.
Developer payload is the main defence against fake purchases. (As suggested by Google guy@netomarin <https://github.com/netomarin> here https://www.youtube.com/watch?v=tRpGcA4IM5Q) Now that purchases using promo code do not return developer payload even if the purchase is initiated within app, there is no defence against fake purchases. Developer payload should be returned irrespective of payment method (credit card or promo code). If the redeeming of promo code happens through play store, we could be asked to provide static developer payload through developer console. So it is easy for google play to provide developer payload in any scenario. Google, Are you working on this critical issue? On Wednesday, March 9, 2016 at 2:38:16 PM UTC+5:30, Jérémy R wrote: > > Hi all, > > We are several developers to experience issue with in-app purchases & > promotion: if the promotion is used inside the app instead of the standard > payment method, the returned developer payload is empty. > A post has been opened on Stack Overflow: > http://stackoverflow.com/questions/34979420/in-app-purchases-made-via-promo-codes-return-empty-developer-payload-string > > I asked the Google Play Developer Support (googleplay-dev...@google.com > <javascript:>) but the answer I received is globally "there is no bug". > > Moreover, as commented in a comment by user greywolf82, when you use the > promotion via the Google Play store, this purchase can't have a developer > payload so it may be a serious security flaw if we can't check the > developer payload validity. > > So, does anyone have a valid developer payload after using a promotion > code? > > -- You received this message because you are subscribed to the Google Groups "Android Developers" group. To unsubscribe from this group and stop receiving emails from it, send an email to android-developers+unsubscr...@googlegroups.com. To post to this group, send email to android-developers@googlegroups.com. Visit this group at https://groups.google.com/group/android-developers. To view this discussion on the web visit https://groups.google.com/d/msgid/android-developers/a2dc7b6d-b405-4575-87e4-ea4583b1b6f8%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.