- Shipped
- September 28, 2026 at 6:34 PM UTC
- Author
- Kamo
- Commit
- b0b624e
kamouniverse.com is the platform's primary apex (kamo-shared-library 0e8cf90f). Sign-in ranks it first for the platform organization, the one organization holding both kamocrm.com and kamouniverse.com, via **************** - TenantRedirectResolver chose the workspace host with its own fewest-labels-then-alphabetical rule, under which kamocrm.com sorts first. So after a Teams or RingCentral OAuth hop the platform's members would have been sent to internal.kamocrm.com while signed in on internal.kamouniverse.com: a different origin, with no session on it, which reads as being signed out. It now uses **************** the rule OrgDomains/OrgApiHosts use. Every other org's answer is unchanged (the primary-apex rule only decides anything for an org that holds the primary apex). - The fallback redirect (an org with no registrable domain) now defaults to **************** where a domainless org works, instead of a kamocrm.com literal; application.yml's local defaults match. Kept (K1): the RingCentral/Teams OAuth redirect URI and every **************** webhook or public base on api.kamocrm.com, and pbx.k3.kluster.kamocrm.com (K2). k8s/ingress.yaml is a dead manifest (not applied by CI, absent from the cluster) and was left alone. Tests: TenantRedirectResolverTest pins the platform organization's answer. mvn clean test: 834 run; the single failure **************** a 3s timing test) passes when run alone.
