KamoCRM

KamoMail binds only an address on a domain the organization holds; the provider needs its right

FixEmailService
Shipped
September 28, 2026 at 4:52 PM UTC
Author
Kamo
Commit
95c58af

The cross-tenant read path parked as SP99-T1-f. A self-registered organization could point its provider at its own IceWarp or Exchange (PUT /api/email/provider checked no right at all), sync to import any address - kamocrm.com staff included - assign the row, switch back to KAMO_MAIL, and MailProviderResolver then bound the shared mail server's password for that address by email. - resolveForMailbox refuses a KamoMail binding whose address is not on a domain in **************** (the org's, or under PARENT_ORG the provider org's too); it answers as a mailbox the member may not open. - PUT /api/email/provider and GET /api/email/provider/oauth/url need MANAGE_EMAIL_SETTINGS, the right every Email settings screen is gated on. Any member could re-point or blank the org's provider before. - MailboxQuotaSyncSweep sizes only accounts on the org's own domains, so an imported row can no longer set another tenant's quota (T1 concern 5). Audited 2026-09-28 (read-only): every mailbox row of every KamoMail org (KamoCRM Inc 30 on kamocrm.com, sp00verify 2 on sp00verify.kamocrm.com) is on a domain it holds, so no legitimate binding changes. SP99 final review I-2.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing