KamoCRM

A session type without its own gate takes no messages, and a session is described only to its readers

FixMediaService
Shipped
September 28, 2026 at 10:28 AM UTC
Author
Kamo
Commit
465eed6

POST **************** authorized CHAT, SUPPORT_TICKET and SOCIAL and then simply ended, so a POST, SYSTEM_BUG or EXEC2EXEC session fell through every gate: any signed-in member of any org who knew the guid could write into another org's bug thread or an executive's conversation with KamoCRM. Every other type, and any type added later, is now refused 403 — a seat included, since those rows mean "has taken part" and each type has its own writer. GET /api/media/sessions/{guid} described any session to anyone signed in; it now takes the transcript read gate. PATCH **************** checked only a sign-in; it now takes the reply rule (the connection's own organization). SP98-D-1.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing