KamoCRM

An alias goes only to a member of the caller's own organization

FixEmailService
Shipped
September 28, 2026 at 7:08 PM UTC
Author
Kamo
Commit
9fbb615

POST /api/email/aliases took any memberId: an administrator could create an alias in their organization that forwards to another tenant's member, and read that member's address back in the response (SP99 T1 concern 3, carried by the final review). The target must now be a member of the session's organization, else 404 before any credential is read. AliasController's own hasRight also takes the open-window rule (SessionRights.godModeOpen).

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing