You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Stripe challenge shows the gross amount and currency, while Connect settlement fields remain server-controlled. The server may apply a connected account, application fee, business-of-record account, transfer destination, and transfer amount after receiving the payer's SPT.
This behavior is required by the Stripe method design and does not let the server exceed the authorized gross amount. In the current implementation, the challenge exposes the authorized total and the receipt identifies the PaymentIntent, but neither records the complete Connect allocation. This is a request for optional payment evidence, not a security or implementation defect.
Impact
Applications with merchant, destination, or platform-fee policies cannot verify or later audit the complete allocation from MPP evidence alone. Two identical payer-visible challenges may use different valid server settlement policies while charging the same total amount.
Expected behavior
Applications would benefit from an optional, non-sensitive commitment or receipt reference identifying the Connect settlement policy used for a payment, while preserving the existing server-controlled mode.
Steps to reproduce
Configure a Connect callback with an application fee, connected account, business-of-record account, and transfer destination at src/stripe/server/Charge.test.ts:134-157.
Obtain the challenge and confirm that these fields are absent at src/stripe/server/Charge.test.ts:159-167. The challenge schema contains no Connect settlement fields at src/stripe/Methods.ts:21-41.
Submit the SPT at src/stripe/server/Charge.test.ts:169-178.
Observe that the Connect fields are applied to the PaymentIntent at src/stripe/server/Charge.test.ts:180-188, while the receipt at src/stripe/server/Charge.ts:165-171 contains only the PaymentIntent reference and optional external ID.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Description
The Stripe challenge shows the gross amount and currency, while Connect settlement fields remain server-controlled. The server may apply a connected account, application fee, business-of-record account, transfer destination, and transfer amount after receiving the payer's SPT.
This behavior is required by the Stripe method design and does not let the server exceed the authorized gross amount. In the current implementation, the challenge exposes the authorized total and the receipt identifies the PaymentIntent, but neither records the complete Connect allocation. This is a request for optional payment evidence, not a security or implementation defect.
Impact
Applications with merchant, destination, or platform-fee policies cannot verify or later audit the complete allocation from MPP evidence alone. Two identical payer-visible challenges may use different valid server settlement policies while charging the same total amount.
Expected behavior
Applications would benefit from an optional, non-sensitive commitment or receipt reference identifying the Connect settlement policy used for a payment, while preserving the existing server-controlled mode.
Steps to reproduce
src/stripe/server/Charge.test.ts:134-157.src/stripe/server/Charge.test.ts:159-167. The challenge schema contains no Connect settlement fields atsrc/stripe/Methods.ts:21-41.src/stripe/server/Charge.test.ts:169-178.src/stripe/server/Charge.test.ts:180-188, while the receipt atsrc/stripe/server/Charge.ts:165-171contains only the PaymentIntent reference and optional external ID.All reactions