KamoCRM

KamoAI internal surface guarded by its own secret

FeatureVOIPService
Shipped
September 27, 2026 at 4:54 PM UTC
Author
Kamo
Commit
d628fe1

/api/voip/internal/** (SP13: AI lines, SIP credentials for LiveKit) takes KAMOAI_INTERNAL_SECRET, not the cluster secret; the cluster prefixes keep theirs. The filter matches the decoded path Spring MVC routes by, so an encoded letter (/api/voip/%69nternal/...) cannot skip either secret.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing