| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
The Mastercard 2-series range is 2221-2720, but the prefix pattern matched 22-27 (i.e. 2200-2799). Numbers in 2200-2220 and 2721-2799 were wrongly accepted as Mastercard, including Mir cards (2200-2204): the same number passed both mir() and mastercard(). Use the precise 2-series sub-ranges. The Mir test cards are now included in the mastercard negative fixtures, which they failed before this change.
| Back | FazBrowse Home | New Git URL |
Summary
mastercard() accepts numbers that are not Mastercard. The Mastercard 2-series IIN range is 2221–2720, but the prefix pattern matches 22|23|24|25|26|27 — i.e. anything from 2200 to 2799. So 2200–2220 and 2721–2799 pass as Mastercard.
This also collides with mir(): Mir cards begin with 2200–2204, so the same number is reported as both Mir and Mastercard.
Reproduction
Root cause
22–27 is much wider than the real 2-series range (2221–2720).
Fix
Match the precise 2-series sub-ranges:
Valid Mastercard numbers (51–55 and 2221–2720) keep validating; 2200–2220 and 2721–2799 are now rejected.
Tests
test_returns_failed_on_valid_mastercard already checks that every other network's cards are rejected by mastercard() — every list except mir_cards, the only omission, because those cards currently pass mastercard(). This PR adds mir_cards to that fixture: they fail on master and pass with the fix. The full test suite stays green and ruff is clean.