KamoCRM

Phone OAuth hops return the platform's members to internal.kamouniverse.com

FixVOIPService
Shipped
September 28, 2026 at 6:34 PM UTC
Author
Kamo
Commit
b0b624e

kamouniverse.com is the platform's primary apex (kamo-shared-library 0e8cf90f). Sign-in ranks it first for the platform organization, the one organization holding both kamocrm.com and kamouniverse.com, via **************** - TenantRedirectResolver chose the workspace host with its own fewest-labels-then-alphabetical rule, under which kamocrm.com sorts first. So after a Teams or RingCentral OAuth hop the platform's members would have been sent to internal.kamocrm.com while signed in on internal.kamouniverse.com: a different origin, with no session on it, which reads as being signed out. It now uses **************** the rule OrgDomains/OrgApiHosts use. Every other org's answer is unchanged (the primary-apex rule only decides anything for an org that holds the primary apex). - The fallback redirect (an org with no registrable domain) now defaults to **************** where a domainless org works, instead of a kamocrm.com literal; application.yml's local defaults match. Kept (K1): the RingCentral/Teams OAuth redirect URI and every **************** webhook or public base on api.kamocrm.com, and pbx.k3.kluster.kamocrm.com (K2). k8s/ingress.yaml is a dead manifest (not applied by CI, absent from the cluster) and was left alone. Tests: TenantRedirectResolverTest pins the platform organization's answer. mvn clean test: 834 run; the single failure **************** a 3s timing test) passes when run alone.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing