Require VIEW_CALL_LOGS for call playback in PHI-handling orgs

FeatureVOIPService
Ya
3 Agosti 2026, 04:04 UTC
Mwandishi
Kamo
Ahadi ya
6d363c0

Recording and voicemail playback checked tenancy and nothing else: any member of the owning org could pull any call in it, transcript included, on extensions that were not theirs. Requiring VIEW_CALL_LOGS outright was not an option — a right can exist in the enum and be granted to nobody, so switching it on for everyone takes the softphone away from the members using it today. Enforcement is therefore scoped to the compliance boundary that makes it necessary. For an org with handlesPhi set, recording audio, per-leg tracks, voicemail audio and the transcript riding inside recording metadata require the right; the refusal is a 403 and lands in the PHI audit trail through the existing denied-path recorders, so probing is visible. For every other org — all of them today — nothing changes, which is what the **************** cases pin down. Known consequence: the ?st= stream-token session carries only (orgId, memberId), so under a PHI tenant the audio-tag path fails closed until the token carries the grant. Recorded in a test rather than left to be discovered.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei