- Shipped
- September 28, 2026 at 4:52 PM UTC
- Author
- Kamo
- Commit
- b55d654
Any member of an organization with no root could add the root victim.kamocrm.com (POST /api/security/domains checked no right). Listing the domains then self-healed it to ownership_verified - no customer can publish a TXT record in the platform's zone - and verifying revokes the name from every other organization, clearing the victim's ownership_verified and is_dns_verified. internal.victim.kamocrm.com then stopped routing to the victim: a cross-tenant sign-in outage and a branding surface. For a host under a platform apex the first holder now keeps it (PlatformHostClaims: another org's root on the name, another org's alias host <label>.<root>, or another org's web alias <label>.<apex>): - POST /api/security/domains needs CONFIGURE_SYSTEM (the right /settings/essential's 'Custom domain' is gated on), the organization's owner, or elevated cross-org access; else 403 MISSING_RIGHT. - Creating or renaming a root onto a held platform host is 409 PLATFORM_HOST_TAKEN, unless the platform does it with an open god-mode window. Organization creation with a typed domain refuses it the same way, before anything is written. - The platform-subdomain self-heal never verifies a second claim, so it can never revoke the holder. A customer's own domain is unchanged: its TXT record settles it. Audited 2026-09-28: no platform-subdomain root or alias host is held by two orgs. SP99 final review I-3.
