- Shipped
- September 4, 2026 at 3:08 AM UTC
- Author
- Kamo
- Commit
- 73b5704
Force Logout deletes sessions, which ends a browser. It does not end a phone: KamoMobile holds a durable device token and mints a fresh session from it immediately, so pressing Force Logout on a lost handset looks like it worked and changes nothing. The new button revokes the devices themselves. It matters more now that KamoMobile can open a fully interactive terminal on the member's dev machine: whoever is holding an unlocked handset has a shell on a box with a cluster-admin kubeconfig until this runs. Also allow-lists the forwarded action. It lands in the upstream PATH, so an unchecked value carrying '..' segments could aim an authenticated POST at a different SecurityService endpoint. Those all authorize themselves, so this is a second line rather than the only one — but the first line should not be 'the HTTP client happens to normalize that'.