question

ycb avatar image
ycb asked ycb published

App billing info fail

Hi clover team,
I found a security fail on app billing info end point
/v3/apps/aId/merchants/mId/billing_info
I can get app billing infos for a merchant by providing a valid token for the app, even if the token is not for this merchant,
I think you check the token only by app not by app and merchant together.
API Token
2 comments
10 |2000

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

ycb avatar image ycb commented ·

Thanks for reply,

Do you have a fixed planing for fixing the issue?

because we use this end point on our app.

0 Likes 0 ·
Raymond Lee avatar image Raymond Lee ycb commented ·

We are planning on fixing the issue, but I currently do not have an time estimate on when it will be done or when it will be released.

0 Likes 0 ·

0 Answers

Welcome to the
Clover Developer Community