- Shipped
- September 28, 2026 at 6:51 PM UTC
- Author
- Kamo
- Commit
- d97b7c8
"Change domain" on /setup/dns for the platform organization showed only "SecurityService error". The button deletes the domain in use and then asks for a new one. For kamocrm.com SecurityService refuses the delete (409 PLATFORM_APEX), because this morning that delete took sign-in down for every organization. The proxy then replaced SecurityService's explanation with a generic string. Separately, the page could never show kamouniverse.com: it picked the domain alphabetically, and every record on it read as unverified. - platformApex.ts: PLATFORM_APEX is kamouniverse.com; kamocrm.com stays in PLATFORM_APEXES. New isPlatformHost, isPlatformApex and platformApexOf helpers match whole labels. serverCanNameTabOrg and the hosted-computer tab icon now treat BOTH apexes as the shared host. Without that, once the primary moved, every domainless tab on internal.kamocrm.com would have been titled with the platform's name. - pickPrimaryDomain and /api/org/current rank the primary apex first. This is the same rule as SecurityService OrgDomains.preferred. - /setup/dns opens on SecurityService's primaryDomain. When the org answers on other domains (only the platform org does), a panel names the primary and lets you view the others. Change domain is hidden for a platform apex. - Record cards show the CNAME target SecurityService reports (the primary apex), plus the A-record alternative: verification now follows a host to the address it finally resolves to. - The DELETE proxy passes SecurityService's own JSON refusal through. Needs dictionary c0f86829 (setup.dns.studio.domains.*, **************** which is already on main.
