Payment retry bug causes double charges despite idempotency keys
A payment system flaw can charge customers twice when a timeout triggers a retry, even when using idempotency keys. The common implementation error involves recording the key and processing the payment as separate non-atomic operations. If the system crashes between these steps, a retry can duplicate the payment. The correct solution requires making the key record and payment transaction a single atomic operation. Additionally, systems must store and return the original response rather than just acknowledging a duplicate request.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in