A streaming subscription with three plans and mid-cycle plan changes. There is no injection here, no IDOR, no tampering with prices or plan ids - everything is calculated server side and every single request you will send is a request the product is designed to accept.
Goal: walk out with a 120 EUR gift card having never added a payment method. Your account starts with 20 EUR of promotional store credit and nothing else.
Account id:
ready
| # | type | detail | prorated | applied | credit |
|---|
Read terms before you touch anything else. Two of the rules in there are both described as
being "in your favour". Ask yourself what happens when both apply to the same amount.
Change plan once in each direction and then open the ledger. Compare the
prorated column with the applied column on both rows. The exact amount is the
same going up and coming down - the applied amounts are not.
Not every pair of plans leaks. Pick the pair whose prorated amount is not a whole number of euros for your remaining days. The biggest price gap is not automatically the best one - check the maths, some pairs divide evenly and gain you exactly nothing.
One round trip is worth about one euro, and you need a hundred of them, so this has to be scripted. Mind the fair-use rule in the terms: too many plan changes in a row with nothing else in between puts the account on hold. Any ordinary account action in between clears it.