- Shipped
- September 28, 2026 at 6:40 AM UTC
- Author
- Kamo
- Commit
- 855076b
The KamoMail server's virtual_domains and virtual_users are shared by every tenant, and nothing stopped one tenant from writing to another's part of them: - POST /api/email/domains put ANY domain into virtual_domains, after which postfix delivers that domain's mail locally for every tenant. It now needs an ownership_verified org_domains root of the org's own covering the domain; a Kamo operator with an open god-mode window may add a *.kamocrm.com host for a test org. - DELETE /api/email/domains/{d} deleted ANY virtual_domains row, cascading every mailbox account on it (all of kamocrm.com). Now only the org's own domain row. - Creating a mailbox, shared mailbox or alias skipped the domain check for every org without an org_email_providers row (all but KamoCRM), so they could create accounts on kamocrm.com. The check now holds for every org and provider. - Mailbox sync imported every server account on any domain the org had merely TYPED into org_domains; resetting the password of such a row took the account over. Sync, password changes, deletes and both self-heals now act only on domains the org holds. What an org holds **************** its ownership-verified, non-platform org_domains roots, plus its EmailService domain rows for hosts under those roots or for platform subdomains - rows only the gated add can write; provider sync no longer imports platform hosts, and a KamoMail sync no longer rewrites a row's status. An org at Google/Microsoft/etc. may also create mailboxes on domains its provider reports VERIFIED, since the provider creates those.
