KamoCRM

Resolve system-user session from OTK for BFF requests

FixSecurityService
Shipped
23 ஏப்ரல், 2026 அன்று 11:29 PM UTC
Author
Kamo
Commit
1361dea

SystemUserConfigController and SystemUserCapabilityController only read the *** cookie. kamo-internal forwards X-OTK without cookies, so SecurityService never saw a session and returned 403 for legitimate top-level owners. Use the same resolution as EnterAsController: prefer OTKPreAuthFilter session attribute, then *** cookie. Extract shared CallerSessionResolver.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing