KamoCRM

A lead you may not open takes no status change and no note

FixSecurityService
Shipped
September 28, 2026 at 10:11 AM UTC
Author
Kamo
Commit
1048ea9

PUT /api/security/leads/{id} and POST /api/security/media/posts checked only the lead's organization, so a member without VIEW_UNASSIGNED_LEADS could change the status of, or post a note on, an unassigned lead the lead page refuses to open. Both now apply the lead GET's per-lead read rule (assigned to anyone, VIEW_UNASSIGNED_LEADS, a free-for-all product, or god), and so does the lead's GET /feed?leadId=, which also stops making a stream for it. The Tool Plane's status and note tools come through these doors as their member and are held to the same rule (SP98-C-6). A guid-addressed comment, like or read now serves only a POST session made in the caller's own organization. Before, any signed-in member who knew a guid could write into any session: another organization's feed, a chat, a system bug. Anything else answers 404. A note on a lead now reaches its author's accept gate. The publish sat after the lead branch's early return, so it never ran.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing