Hello,
I was reading the spec and I don't really understand how the merchant domain or payment details are authenticated. How do you prevent such a scenario:
- A user visits
secure-legit-trusted-store.com, adds a $1000 laptop to their cart and initiates a payment
secure-legit-trusted-store.com backend visits buy-crypto-online.com and initiates a payment for $1000
secure-legit-trusted-store.com relays the request from buy-crypto-online.com, but changes details to The best laptop
- User confirms the payment
secure-legit-trusted-store.com relays the response to buy-crypto-online.com