KamoCRM

Kamouniverse.com is a platform apex, not a tenant domain

FeatureSecurityService
Se descapó
28 de septiembre de 2026 a las 5:44 UTC
Autor
Kamo
Compromit
79799ed

login.kamouniverse.com and register.kamouniverse.com become the platform's KamoUniverse sign-in and sign-up doors, backed by a root org_domains row on the platform organization beside kamocrm.com. Judged against kamocrm.com alone, that host resolves to the platform organization and takes the HOST-SCOPED path: only the platform's own members could sign in there, ?org= was ignored, and a member of any other workspace was refused. PlatformApexes holds the list (kamo.platform.apexes, default kamocrm.com,kamouniverse.com; kamo.platform.apex stays the PRIMARY): - isPlatformHost: every platform apex offers the workspace picker. - The fallback workspace host for a domainless organization is internal.<primary apex> whichever door the password was typed at — on the password path, the picker's /session/select, and after a second factor. The platform organization itself still lands on internal.kamocrm.com (OrgDomains.preferred: kamocrm.com sorts first). - OrgNetworkEnterPolicy skips platform apex rows, so a platform root row awaiting certificates can no longer mark the platform "setup incomplete" by winning the unordered first-root-row race. - DomainController's Kamo-owned-zone special cases and the SPF / DKIM / DMARC advisories recognise *.kamouniverse.com as they do *.kamocrm.com. - "kamouniverse" is a reserved alias: it is the theme folder those two doors paint, and an organization holding it would rewrite that screen with its first branding save.

Todos los cambios

Como lo que ves enviaste?

Todo llega a su espacio de trabajo por sí solo. Comience en el plan gratuito y lea esta página de nuevo en un mes.

Arranzar gratis para siempreVer Precios