Enter-as session uses target org security provider and optional targetMemberId

FixSecurityService
Shipped
April 23, 2026 at 11:39 PM UTC
Author
Kamo
Commit
01feb45

Enter-as was setting Redis securityOrgId from the user global security_provider, while login sets it from the target org FQDN chain. That mismatch made cross-domain hand-offs look like the source/provider org. Resolve securityOrgId from the target Organization.securityProvider like login. When the client sends targetMemberId (my-networks row), load that Member by id and verify it belongs to the caller and targetOrgId before creating ***/OTK.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing