Post

Replies

Boosts

Views

Activity

Comment on Account Deletion for Apple Store Reviewers
Here is the exact reason given for the rejection: We discovered one or more bugs in your app. Specifically, when attempting to login using the email address provided an error appears on the screen. Seeing an error on the screen in this case is expected because in a previous review, they deleted the account we provided them with. Now they cannot log in with that account anymore. Yes, we have already confirmed they have deleted the account. We did not explain to them not to delete their account, but maybe this is what we need to do to prevent them from testing this part of the app? Since there is not much documentation on how 5.1.1 is supposed to be tested by Apple reviewers, I don't really understand what we're expected to provide them (new credentials every time we submit in case they test to delete?). I'm just not really sure how other developers will be solving this problem. It seems like everyone will be in the same boat as soon as they add this functionality to their app by June 30. When we asked them what we should do and explained exactly what I explained above in my first post, we received a canned response with links to developer docs and this forum.
Topic: Privacy & Security SubTopic: General Tags:
Apr ’22
Comment on Account Deletion for Apple Store Reviewers
Thank you. The issue with offering a "click to un-delete" feature is that Apple specifically says "It’s insufficient to only provide the ability to temporarily disable or deactivate an account." https://developer.apple.com/news/?id=i71db0mv. Also, it is generally recommended for security reasons to give a generic error with as little detail as possible about why the user can't log in to prevent giving additional information to potential hackers.https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html#authentication-and-error-messages
Topic: Privacy & Security SubTopic: General Tags:
Apr ’22