KamoCRM

Enter-as session uses target org security provider and optional targetMemberId

FixSecurityService
Shipped
23 ஏப்ரல், 2026 அன்று 11:39 PM UTC
Author
Kamo
Commit
01feb45

Enter-as was setting Redis securityOrgId from the user global security_provider, while login sets it from the target org FQDN chain. That mismatch made cross-domain hand-offs look like the source/provider org. Resolve securityOrgId from the target Organization.securityProvider like login. When the client sends targetMemberId (my-networks row), load that Member by id and verify it belongs to the caller and targetOrgId before creating ***/OTK.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing