RequestNetwork / request-apps

Request network Dapps monorepo
MIT License
5 stars 12 forks source link

[pay] anyone can pay a request, even the payee #39

Closed MantisClone closed 1 year ago

MantisClone commented 1 year ago

Question

The pay request app allows anyone to pay a request, not just the specified payer. Is this intended behavior? Or is this a bug?

Screenshots

Request details From (payee): 0x7eB023BFbAeE228de6DC5B92D0BeEB1eDb1Fd567 To (payer): 0x519145B771a6e450461af89980e5C17Ff6Fd8A92 Screenshot from 2022-11-18 16-55-30

Anyone who connects to the https://pay.request.network/<requestId> page will be prompted to pay...

Including the payee: Screenshot from 2022-11-18 16-48-22

Or a 3rd party: Screenshot from 2022-11-18 16-52-08

MantisClone commented 1 year ago

The resulting PDF after paying a request has a separate field for "Paid by" so perhaps the ability for anyone to pay the invoice is by design.

Image

MantisClone commented 1 year ago

I think anyone can pay the invoice. This is by design.