KamoCRM

A session type without its own gate takes no messages, and a session is described only to its readers

FixMediaService
Se descapó
28 de septiembre de 2026 a las 10:28 UTC
Autor
Kamo
Compromit
465eed6

POST **************** authorized CHAT, SUPPORT_TICKET and SOCIAL and then simply ended, so a POST, SYSTEM_BUG or EXEC2EXEC session fell through every gate: any signed-in member of any org who knew the guid could write into another org's bug thread or an executive's conversation with KamoCRM. Every other type, and any type added later, is now refused 403 — a seat included, since those rows mean "has taken part" and each type has its own writer. GET /api/media/sessions/{guid} described any session to anyone signed in; it now takes the transcript read gate. PATCH **************** checked only a sign-in; it now takes the reply rule (the connection's own organization). SP98-D-1.

Todos los cambios

Como lo que ves enviaste?

Todo llega a su espacio de trabajo por sí solo. Comience en el plan gratuito y lea esta página de nuevo en un mes.

Arranzar gratis para siempreVer Precios