KamoCRM

Clear the session cookie on the bare apex, not ".apex"

FixSecurityService
Shipped
September 28, 2026 at 9:28 AM UTC
Author
Kamo
Commit
bc54945

Logout built the cookie domain as ".kamocrm.com". Tomcat's RFC 6265 cookie processor refuses a leading dot and throws, so logout answered 500 "Logout failed" after it had already deleted the session. A bare Domain=kamocrm.com covers every subdomain just the same.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing