KamoCRM

Only verified RingCentral webhooks are processed; calling needs a seat

FixVOIPService
Shipped
September 24, 2026 at 8:38 PM UTC
Author
Kamo
Commit
93fc7c2

The legacy path that processed a RingCentral call or SMS event with no instanceId, trusting the payload's own to-number, is removed together with its 2026-10-13 cutoff. An event that does not verify is logged and answered 200 with no processing. The unscoped handleCallEvent/handleInbound overloads that only that path called are removed too. GET /api/voip/sip/credentials and GET /api/voip/turn/credentials refuse a member whose seat does not cover CALL with the shared 403 SEAT_REQUIRED body, before any VOIP or TURN configuration is read (KamoAI SP00 D3, D7). The deployment mounts nats-user-voip, redis-auth and kamoai-internal-auth.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing