- Shipped
- September 28, 2026 at 4:52 PM UTC
- Author
- Kamo
- Commit
- 95c58af
The cross-tenant read path parked as SP99-T1-f. A self-registered organization could point its provider at its own IceWarp or Exchange (PUT /api/email/provider checked no right at all), sync to import any address - kamocrm.com staff included - assign the row, switch back to KAMO_MAIL, and MailProviderResolver then bound the shared mail server's password for that address by email. - resolveForMailbox refuses a KamoMail binding whose address is not on a domain in **************** (the org's, or under PARENT_ORG the provider org's too); it answers as a mailbox the member may not open. - PUT /api/email/provider and GET /api/email/provider/oauth/url need MANAGE_EMAIL_SETTINGS, the right every Email settings screen is gated on. Any member could re-point or blank the org's provider before. - MailboxQuotaSyncSweep sizes only accounts on the org's own domains, so an imported row can no longer set another tenant's quota (T1 concern 5). Audited 2026-09-28 (read-only): every mailbox row of every KamoMail org (KamoCRM Inc 30 on kamocrm.com, sp00verify 2 on sp00verify.kamocrm.com) is on a domain it holds, so no legitimate binding changes. SP99 final review I-2.
