KamoCRM

Basic sign-in asks SecurityService's real credential check

FixEmailService
Shipped
September 28, 2026 at 9:42 AM UTC
Author
Kamo
Commit
9196272

DavAuthFilter posted Basic credentials to **************** which never existed (405), so every username-and-password sign-in from iOS or DAVx5 was answered 401 (SP07 T37). It now posts to SecurityService POST /api/internal/dav/sign-in with X-Internal-Auth, relaying the client's X-Forwarded-Host, X-Forwarded-For, X-Real-IP and User-Agent so the lockout and access rules judge the phone, not this pod. - 200 proceeds as that member and workspace (ids read as text; they pass 2^53); - 401 challenges again; 403 only for SecurityService's BLOCKED verdict; 429 carries Retry-After; anything else, or no answer, is 503 rather than a password prompt; - workspace-backslash-username names the workspace (the web's ?org= hint), for a member of several workspaces on the platform host; - an accepted password is remembered for two minutes (salted per process), so a sync is one password hash rather than one per request; a refusal is never remembered; - a malformed header or an empty password is answered 401 without asking.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing