Permission to pay your money, please!
I’m trying to pay a SaaS bill online, and I run into the following issue. I have insufficient permissions to pay the invoice on the account. No insufficient funds, which is something that you’ll routinely run into when dealing with payment processing. But insufficient permissions!
Is… paying something an act that requires permissions? That something that happens? Can I get more vulnerabilities like that? When I get people to drive-by pay for my bills?
I can’t think of a scenario where you are prevented from paying to the provider. That is… weird.
And now I’m in this “nice” position where I have to chase after the provider to give them money, because otherwise they’ll close the account.
Comments
Maybe an attack vector could be paying for someone elses service, then doing a chargeback later, causing the account to be closed?
Jag,
Chargeback is a concern, but that seems like a far off scenario. And the original customer is still expecting to pay the invoice.
Yeah I agree it's a longshot. Just trying to imagine what they could be worried about.
Scott, Ouch, that is nasty. This gets really complex if you have any non trivial billing setup.
For example, for large bills, if you need to call the CC to get pre-auth, that means that you need to be able to click "pay" on the website while on the call with the CC company. Makes it awkward to deal with.
It's worse when we are talking about paying by wire,etc. Since you may need to have back & forth with the provider (here is the wire transfer details, etc).
Comment preview