docs: Recommend not using email address in payload string

am: 74916a5682

* commit '74916a5682e3cc0918067a3e3d4fd09f7404af6f':
  docs: Recommend not using email address in payload string
This commit is contained in:
Andrew Solovay
2016-02-01 19:51:30 +00:00
committed by android-build-merger

View File

@@ -100,6 +100,12 @@ Google Play returns this string together with the purchase details.</p>
made the purchase, so that you can later verify that this is a legitimate purchase by
that user. For consumable items, you can use a randomly generated string, but for non-
consumable items you should use a string that uniquely identifies the user.</p>
<p class="note">
<strong>Note:</strong> Do not use the user's
email address in the payload string, since that address may change.
</p>
<p>When you get back the response from Google Play, make sure to verify that the
developer payload string matches the token that you sent previously with the purchase
request. As a further security precaution, you should perform the verification on your