Skip to content

[Agricola] AGR-2026-096: Receipt parser accepts non-success statuses #222

Description

@mpp-agricola

AGR-2026-096 — Receipt parser accepts non-success statuses

Last observed by the head-to-head audit at 2026-09-14T09:17:13.387847Z.

Audited heads

Target Repository Commit Conformance Semantic review
typescript wevm/mppx 3c14a65a7ea5 Complete Reference
java stripe/mpp-java ca57f0998545 Complete Complete
go tempoxyz/mpp-go 9fcf9a47c61b Complete Complete
python tempoxyz/pympp 7988d1cda5c4 Complete Complete
ruby stripe/mpp-rb 3b9e2923c67b Complete Complete
rust tempoxyz/mpp-rs d859a13d74ef Complete Complete

Finding

  • Fingerprint: semantic:receipts/require-success-status
  • Source: semantic
  • Affected SDKs: java
  • Clean SDKs: none
  • Not reported by semantic review: go, python, ruby, rust
  • Canonical reference: draft-httpauth-payment-01 §5.3 (Payment-Receipt Header): status MUST be "success"
  • Severity: medium
  • Confidence: high

Evidence

SDK Canonical evidence SDK evidence Suggested test
java shape.status — Defines receipt status as the literal value "success"; Receipt.from and deserialize enforce this schema. parsePaymentReceipt — Reads status as an arbitrary string and rejects only a missing value. Decode a syntactically valid receipt whose status is "failed" and assert that receipt parsing rejects it.

java: Canonical mppx validates the receipt status as the literal "success". The Java parser only checks that status exists, so values such as "failed" are accepted as valid receipts. Consumers may consequently treat an error-like or forged result as a protocol-valid successful payment receipt.

Available /ag commands

Post a command as a new comment. Only configured maintainers can run these commands.

Command What it does
/ag status Reports the current state of linked remediation pull requests.

/ag fix is unavailable for java because the affected SDK is configured for notification-only automation.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agricolaIssues managed by AgricolajavaPull requests that update java code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions