KamoCRM

Use OTKPreAuthFilter attributes instead of re-validating OTK in NotesController

FixSecurityService
Shipped
23 மார்ச், 2026 அன்று 1:56 AM UTC
Author
Kamo
Commit
cdb3b68

The OTKPreAuthFilter already consumes and validates the OTK, storing the session data in request attributes. NotesController was trying to re-validate the already-consumed OTK, causing authentication failures. Now reads from request attributes first, matching MemberController pattern.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing