I started to implement Google Play Billing flow (Subscriptions only) for simple use cases but surprisingly there are quite limited articles showing how to do it in an optimal way. ClassyTaxi example (https://github.com/android/play-billing-samples/tree/3f34105c34e2ed2e88055ccf2b04088e8a5fd3a2/ClassyTaxiJava) is in my opinion over-complicated and mix some functions (e.g. acknowledging by Android app instead on back-end server).
Simple case:
- App is built around Firebase services (Auth, Firestore, Cloud Functions, etc.)
- Subscriptions are linked to the App user
- Only one subscription type (Premium access), billed monthly or yearly
My billing flow for new purchases:
- Android app starts BillingClient based on the subscription billing frequency chosen by the user
- After successful payment processing, BillingClient sends a notification via RTDN/PubSub
- Cloud Function processes that notification gets all Purchase data (
Purchases.subscriptionsv2:get), verify it, stores in Firestore ("PurchasesCollection") with userId, and acknowledges - (Optional) Send FCM notification to all user devices about SubsctiptionState change
- Android app listens "PurchasesCollection" to react to any Purchase change
With this approach, the Android app is just listening to Firestore changes and not making any Purchase processing activities as all of them are done on the server side.
In case of any Purchase changes (cancellations, pausing, expiring, etc.) Cloud Function will receive notification via RTDN and updates existing purchase, so the Android app will always get the most recent Subscription status and data.
- Are there any drawbacks or security issues I didn't take into account?
- In case the Android app just needs to confirm if a user is entitled to receive Premium access would it be sufficient to make a simple check
expiryTime = Future(for at least one purchase from the list of all users' purchases)? - What is the most optimal and secure flow for this simple case?