KamoCRM

Pin the bare cookie domain against Tomcat's own cookie processor

TestSecurityService
Shipped
September 28, 2026 at 10:11 AM UTC
Author
Kamo
Commit
2a46b9d

bc54945 stopped logout clearing *** on ".kamocrm.com", which Tomcat's RFC 6265 processor refuses by throwing from addCookie: logout answered 500 after the session was already deleted, about 170 times in the week before the fix. It had no test, and MockHttpServletResponse accepts any Domain, so the base domain is now a helper and the test runs the real processor over what logout sends, and over the leading dot it refused (SP98-C-7).

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing