KamoCRM

A lead's notes stream, addressed by its guid, keeps the lead's own read rule

FixSecurityService
Shipped
September 28, 2026 at 4:51 PM UTC
Author
Kamo
Commit
eff32c0

Every note on a lead now sends the lead stream's guid on /topic/media/feed/<orgId> (SP99-T3), which any member of the organization may subscribe to. The guid-addressed post endpoints checked only the organization (SP98-T3), so a member who may not open a lead could read its first note (GET /posts/{guid}) and write notes onto it (POST /posts/{guid}/comments) - around SP98-C-6's per-lead rule. Read, comment, like, edit and delete by guid now go through one gate: a POST session of the caller's organization that is either a lead's stream the caller may open (LeadViewGate, the lead GET's rule; the lead found through media_session_post.lead_id) or the organization's own feed. Anything else - a stream detached from a deleted lead, an orphan - answers 404. createPost and LeadCallbackService now bind a new lead stream to its lead, as getFeed and LeadReassignmentNoteService already did. Production: the one lead stream made without its lead (session 724b6446-..., lead 1189894336349536262) was bound by **************** before this deploy (UPDATE 1; reversal in the file). SP99 final review I-1.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing