ResellerAPI::processData() is the whitelist every reseller line, MAG and
Enigma2 save goes through. Two fields in it could be turned on other
people's subscriptions:
- pair_id: a new line stored whatever id was sent. Pairing copies the paired
line's expiry and bouquets onto this one on every renewal
(MagService::syncLineDevices), so a reseller could buy the cheapest line
paired to another reseller's paying customer and ride that subscription
for free. MAG and Enigma2 saves already required the paired line to be
the reseller's own; now every type does.
- trial: accepted on an edit, where it reset the expiry for trial_credits
(usually 0). The trial quota counts lines by created_at, which an edit
does not change, so any existing line could be extended forever. The
forms only send it when creating; the API now does the same.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V2uBUbGApb4A7Rbcoi7dxA