KamoCRM

A reply may quote only a message in its own conversation

FixMediaService
Shipped
October 4, 2026 at 7:47 PM UTC
Author
Kamo
Commit
466f019

The member chat send resolved the client's parentId with a bare lookup by id and built the reply quote from whatever it found: the parent's text, its author's name and member id went out on the conversation's live frame and in the response. Anyone holding another message's id could have it quoted into a conversation of their own, across conversations and orgs. ReplyParents is now the one rule for every path that turns a client parentId into a thread parent: the parent must belong to the session the reply is posted into. Anything else is refused 400 PARENT_NOT_IN_CONVERSATION, the same answer for a message elsewhere and a message that does not exist, so the refusal cannot probe ids. The chat send returns it directly; Exec2Exec posts and bug-report comments throw it and ReplyParentAdvice answers. Those two already refused a foreign parent but told 'no such message' apart from 'another conversation'. The dormant NATS chat handler takes the same rule. A malformed id keeps its old meaning on each path.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing