KamoCRM

Record the SecurityService unauthenticated-endpoint triage

Docskamo-internal
Shipped
19 ஆகஸ்ட், 2026 அன்று 1:52 AM UTC
Author
kamo
Commit
94d6744

Three fixed, the rest explained. The headline number needed narrowing three times and the first two attempts were wrong the same way — enumerating helper names rather than detecting structurally — so the document says plainly that a baseline of "unguarded" endpoints is evidence to investigate, not a finding to report. 370 entries: 142 MLOS, 150 that do refuse callers through a helper the ratchet does not follow, 12 in the deliberately-anonymous borrower portal, and most of the remainder correctly public. Fixed: DiagnosticsController (all four, including a Redis session enumerator and an environment dump filtered by denylist), **************** (the whole organization estate), and a test stub deleted. 370 to 364. Left with reasons: EntitlementController is the same trust-the-proxy-header problem as KamoLOS and cannot be fixed in the service without breaking the working path, and the organization lookups are plausibly pre-auth by necessity where the real concern is that they return entities rather than DTOs.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing