KamoCRM

OAuth return URLs accept both platform consoles; webinar cancel links keep the page that exists

FixMediaService
Shipped
September 28, 2026 at 6:33 PM UTC
Author
Kamo
Commit
767d86c

kamouniverse.com is now the platform's primary apex (kamo-shared-library 0e8cf90f): OrgLinkHosts falls back to it, and ROOT_PREFERENCE makes it the platform organization's own live domain. Two consequences here: - OAuthReturnUrlPolicy (Meta and Canva connect) accepted exactly one platform console: the platform organization's internalOrigin. That is now internal.kamouniverse.com, so a member signed in on internal.kamocrm.com was refused their own return URL and redirected to the other origin, where their session does not exist. Recognition is add-only: internal.<every PlatformDomains apex> is accepted for every organization, after OrgLinkHosts' own answer (which stays first and stays the fallback). - WebinarEmailNotifier built the attendee's cancel link as www.<link root domain>/webinar/cancel/<token>. For the platform organization and every domainless one that is now www.kamouniverse.com, the KamoUniverse site, which answers that path with a 404. The page is kamo-marketing's on www.kamocrm.com (still served), so a platform-apex root keeps naming it. An organization's own live domain is unchanged. Tests: new cases for both (both consoles accepted whichever the platform ranks first, look-alikes refused; platform-apex cancel links); the tests that pinned the platform fallback to kamocrm.com (theme/internal/meet hosts) now expect kamouniverse.com, which is what the shared library answers. mvn clean test: 1688 run, 1 failure = OrgDomainRuleGuardTest flagging MeetLinks.java:23, which is pre-existing on origin/main (6c4a7e2) and unrelated.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing