KamoCRM

File new accounts under the org of the domain, not kamocrm

FixSecurityService
Shipped
6 ஜூலை, 2026 அன்று 8:38 PM UTC
Author
Kamo
Commit
e00d60b

/register bound the new member's org to the request Host, but the org signal never survived the hop: kamo-register proxies every signup to the shared api.kamocrm.com and the ingress rewrites X-Forwarded-Host to that shared host, after which the getServerName() fallback resolved to api.kamocrm.com. Every signup — regardless of which org's register.<org>.com the user came from — was therefore filed under the top-level platform org (kamocrm). Take the host from the request BODY (proxy-immune), resolve it with the shared alias-fallback resolver (register.optionone.com -> optionone), and drop the getServerName() fallback so an unresolved host fails closed (400) instead of defaulting to this service's own host. X-Forwarded-Host remains only a legacy fallback. OrganizationController's branding lookup now reuses the same resolver so branding and the account's org resolve a subdomain identically.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing