KamoCRM

Pin the status-label body an org sends to drop a label

TestSecurityService
Shipped
2 செப்டம்பர், 2026 அன்று 2:54 AM UTC
Author
Kamo
Commit
24b0ef1

The two shapes that used to fail: an empty list, which is what clearing the last remaining label sends and what the handler rejected as malformed, and an entry carrying a blank label, which is the removal itself and must reach the service rather than be filtered out on the way in. A body with no labels key at all is still a 400, and an unauthenticated caller still gets 401 without the service being touched — both asserted here so the looser body parsing does not quietly loosen the guard rail with it.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing