Resolve system-user session from OTK for BFF requests

FixSecurityService
Shipped
April 23, 2026 at 11:29 PM UTC
Author
Kamo
Commit
1361dea

SystemUserConfigController and SystemUserCapabilityController only read the *** cookie. kamo-internal forwards X-OTK without cookies, so SecurityService never saw a session and returned 403 for legitimate top-level owners. Use the same resolution as EnterAsController: prefer OTKPreAuthFilter session attribute, then *** cookie. Extract shared CallerSessionResolver.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing