KamoCRM

Only cache-invalidate genuinely-invalid keys, not origin-denied (prevents valid-key DoS)

FixAPIService
Shipped
15 ஜூலை, 2026 அன்று 11:42 PM UTC
Author
Kamo
Commit
0896154

On a cold Redis cache, a valid public-chat key with a wrong/absent Origin was cached as INVALID for 60s, denying the correct origin's requests for that window. Both the HTTP and WebSocket cold-cache fallbacks now distinguish **************** null return (genuinely invalid/inactive key or downstream error - safe to cacheInvalid) from a ValidationResult(valid=false, ...) return (valid key, origin denied - reject this request only, cache left untouched).

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing