KamoCRM

A PBX ring event rings only members of the key's own org

FixVOIPService
Shipped
September 28, 2026 at 2:19 PM UTC
Author
Kamo
Commit
012b0e6

APIService vouches for the API key's org in X-Org-Id and takes the phone server id from a header the key holder writes. The ring seam ignored the org, so any key allowed to ring could ring another org's members by naming that org's server. Only a server of the vouched org rings now (404 INSTANCE_NOT_FOUND otherwise, as V7's policy pull answers); a missing org is 400. Needed now that every PBX helper's upload key may ring.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing