TapTrust Federal — Teller Playground

banking admin·Easy
time to bug
00:00
median 06:30
teller.taptrustfederal.test
live

TapTrust Federal — Teller Console

The internal teller/admin view of the same fictional bank. Look up any customer, inspect the full account ledger (including teller-only notes), and work the transfer approval queue. Open the Client playground in another session to compare what each view discloses for the same account — that seam is where several of these bugs live.

Customer Lookup

Transfer Approval Queue

No approvals.

Investigate the API

Hit the TapTrust Federal teller/admin REST API directly — same requests the console above makes, plus anything else in its own catalog. Runs from your browser using your own session; nothing here can reach another app or reveal the answer key.

API Console

Same-origin only · uses your own session
Headers & body (optional)

Known Intentional Issues (14)

TT-FE-01medium

Transfer amount input silently truncates sub-cent precision instead of rejecting it

On the Transfer form, enter 10.005 as the amount and submit. Expect a validation error. Actual: the transfer submits successfully for a rounded amount with no warning.

TT-FE-02high

Account balance shown on the client dashboard does not refresh after a successful transfer

Note the checking account balance, transfer $10 out, and check the balance shown on the dashboard immediately after the success toast. Actual: balance is unchanged; a manual reload shows the correct lower balance.

TT-FE-03high

Transfer submit button is not disabled while a request is in flight, allowing duplicate submissions

On the Transfer form, fill valid fields and double-click Submit quickly. Inspect the network tab. Actual: two POST requests fire instead of one.

TT-FE-04high

Teller-only internal note field is included in the client-facing account payload

Log in as the client demo user, open the Accounts view, inspect the Network tab response for GET /api/banking/accounts. Actual: each account object includes an internalNote field with teller-only text.

TT-BE-01high

Concurrent transfers from the same account can both pass the balance check and overdraw the account

Fire two concurrent POST /api/banking/transfers requests from acct-3001 (balance $450.12) for $300 each. Expect the second to fail with insufficient funds. Actual: both succeed, leaving the account balance negative.

TT-BE-02high

Idempotency-Key header on the transfer endpoint is accepted but not enforced

POST /api/banking/transfers twice with the same body and the same Idempotency-Key header. Expect one transfer to post. Actual: two separate transactions are created and the balance is debited twice.

TT-BE-03medium

Repeated small transfers accumulate floating-point drift in the stored account balance

Transfer $0.10 out of acct-2001 ten times in a row via the API and sum the expected debit ($1.00). Compare the account's final balanceCents to balanceCents_before - 100. Actual: off by 1 cent after repeated transfers due to float round-trip.

TT-BE-04high

The teller approval-queue endpoint does not verify the caller holds the teller/admin playground session

Log in as the client demo user (not the teller). Send POST /api/banking/admin/approvals/appr-5001/decision with {"decision":"approved"} directly. Expect 403. Actual: 200, and the transfer is approved.

TT-BE-05high

Transfer endpoint accepts a negative amount and credits the sender instead of rejecting the request

POST /api/banking/transfers with amountCents: -5000. Expect 400. Actual: 200, and both accounts' balances increase.

TT-BE-06high

Transfer endpoint allows outbound transfers from an account still in pending_review (KYC-pending) status

POST /api/banking/transfers from acct-4001 (status pending_review) for $10. Expect 403. Actual: 200, and the transfer succeeds.

TT-API-01high

GET /api/banking/accounts/:id returns account data for an account the session's customer does not own

As the client demo user (owns acct-1001/acct-1002), GET /api/banking/accounts/acct-2001 (owned by a different customer). Expect 403/404. Actual: 200 with acct-2001's real balance.

TT-API-02medium

Transaction history pagination skips a page of results

GET /api/banking/transactions?accountId=acct-1001&page=1&pageSize=2 then page=2&pageSize=2. Expect page 2 to start where page 1 left off. Actual: one transaction is skipped between pages.

TT-API-03medium

Transfer endpoint ignores the account's overdraft limit and blocks any transfer exceeding the raw balance

POST /api/banking/transfers from acct-2001 (balance $968.30, overdraft limit $100.00) for $1000.00. Expect success (within overdraft). Actual: 400 insufficient funds.

TT-API-04medium

Teller ledger view shows a stale balance for an account after the teller's own approval action changes it

As the teller, approve appr-5001 (a pending wire from acct-3001), then look up acct-3001 in the Customer Lookup panel. Expect the reduced balance. Actual: the balance shown is unchanged from before the approval.

focus mode hides the rails — just you and the broken app