You're missing the point here. The developer isn't given any guidance on what needs tightening. This shouldn't be guess and check. These rules impact this developer's livelihood. They should be well defined, documented, and communicated.
You're missing the point here. The developer isn't given any guidance on what needs tightening. This shouldn't be guess and check. These rules impact this developer's livelihood. They should be well defined, documented, and communicated.
Let this be the millionth lesson of "the perils of building on a platform instead of on a protocol".
What do you think they should be providing? Honest question, I have some ideas but they all feel very tricky/error prone to implement.
For the record, I actually agree with you that this is a good policy and will be a positive outcome for users. But while you seem to agree that Google could have handled this better, you're not doing a good job of acknowledging just how developer-hostile Google was here, which is why you're getting a lot of pushback.
> At the very, very least, they could identify which of the permissions are in violation
If they've flagged this through user reports of the permissions being too wide then they may not actually know which permissions need to be changed. This is purely speculation though.
How can they not know? They decide whether the update is accepted or rejected, and there's somebody or something at google that makes that decision, so google has to know.
If they didn't know what permissions need to be changed, how is the accept/reject decision made? Something like "accept the fourth try if the developer makes it that far because it is probably an improvement?"
Sure, the first notice may have come from user flags, and the motivation for those flags is unknowable.
But it's been rejected again, after substantial permissions pruning.
Either they know why they rejected the update, in which case they should tell the developer; or they don't know why they rejected the update, in which case they're holding developers hostage to an inscrutable black box.
Both scenarios are shitty.
You are certainly within your rights to state things divisively if it pleases you. I was merely suggesting how you might make your point in a way people will agree with you.
If they've flagged this through user reports of the permissions being too wide then they may not actually know which permissions need to be changed.
Even if this were true,
1) what about the update that narrowed the permissions, surely Google knew which permissions remained in violation? Remember, it was the rejection of that update that prompted this post
2) user reports of permissions being too wide should also be required to identify the specific permission that is in violation. That would not only help the developer, but also help Google make the decision on whether to ultimately ban the extension
3) Google should have clearly stated in the initial message that they hadn't actually verified that the alleged violations are occurring