KamoCRM

Live Change Log

Every feature, fix and improvement, posted as it ships. Nothing is held back for a launch.

15,120
Total Changes
5,169
Features
4,935
Fixes
30
Projects
Filter by project
All Projects15,120AIService197APIService161BillingService143ConversionService107DaemonService129DocsService215ESigService88EmailService518InitializerService318KBService105KlusterServices697MCPGatewayService85MediaService546RAGService71SecurityService1,658TranslateService55VOIPService205VectorService11kamo-apps25kamo-asterisk-support24kamo-capcha17kamo-capcha-widget4kamo-internal6,937kamo-login330kamo-marketing625kamo-nowww20kamo-register213kamo-shared-library1,455kamo-signer-monorepo53kamolos108
Filter by type
All TypesBuild11CI523Chore738Docs2,167Feature5,169Fix4,935Other986Performance157Refactor274Revert23Style42Test94Upgrade1
September 23, 2026
ChoreSecurityService

No live credentials in application.yml defaults

The local-development defaults carried the database OWNER's password (${DB_PASSWORD:<literal>}), and apiservice/securityservice also the live changelog webhook ...

Kamo·5d ago
FixSecurityService

Gate the API on the app, not only the screen

The settings page and the nav option both check organization.isHostedComputers, and until now that was the whole gate. AppAvailabilityInterceptor never mapped /...

Kamo·5d ago
FeatureSecurityService

Human/AI members, phonetic names, role requirements; fix position saves wiping security

Members - Create, create-team-member and bulk-create accept `intelligenceType`, `namePhonetic` (new accounts only, like the name), and for AI accounts `aiSupe...

Kamo·5d ago
FeatureSecurityService

The browser-facing surface, and the second Guacamole gateway

SecurityService is the trust boundary for Hosted Computers. It holds the session, the rights and the org chart; ComputeService holds the Kubernetes credentials ...

Kamo·6d ago
FixSecurityService

Intake endpoints show exact received/imported counts from the intake ledger

The Lead Intake settings list showed total_received / total_processed / last_received_at straight off the endpoint row, where they were bumped once per payload ...

Kamo·6d ago
PerformanceSecurityService

Manage-Credits and Leads-Available read the lead ledgers once instead of counting per row

/leads/credits (GET /api/security/credits/manage) counted the lead pool once per allotment row — ~8 s apiece against one org's 796k-lead pool — then once more g...

Kamo·6d ago
September 19, 2026
FixSecurityService

Normalize memberId when relaying line add/update requests

The browser keeps member ids as strings to avoid IEEE-754 rounding on CockroachDB unique_rowids. Normalize to Long before relaying so the credit lands on the in...

Kamo·1w ago
September 18, 2026
FixSecurityService

The account view names its primary member

GET /customers/{uid} sent the primary member only as primaryMemberId, while the account view reads a primaryMember object — so its Primary member row read "---"...

Kamo·1w ago
FeatureSecurityService

The member card carries the wallpaper their desktop shows

GET /members/{id}/card gains "wallpaper" for the card's header, resolved the way the console backdrop and the profile hero resolve a member's desktop: none when...

Kamo·1w ago
FixSecurityService

An account note names the member who wrote it, not "System"

GET /customers/{uid}/notes sent each note's authorMemberId but no authorName, and the account view shows a note with no name as written by the system — so every...

Kamo·1w ago
FeatureSecurityService

One rule for what a member may do with another, served per member and per roster row

The same five actions — chat, call, email, meet, view profile — were offered from three places in kamo-internal (the Interaction Center row, the chat hex-head p...

Kamo·1w ago
September 17, 2026
FeatureSecurityService

The demos booked on a lead, on the lead

GET **************** The lead page's Webinars section has called /api/webinar/leads/{id} since it was written and nothing ever served it — the live API answers ...

Kamo·1w ago
FixSecurityService

Short one-time codes can no longer be guessed without limit

Every short code the platform mails or texts was checked with no count: - POST /api/recover/email/verify-code took the 8-hex-character reset code ALONE and mat...

Kamo·1w ago
FixSecurityService

Securityservice never stores a password as typed

Two writers put plaintext into USERS.PASSWORD. Both called User.encodePassword(), which needs a static encoder that only initializerservice ever sets **********...

Kamo·1w ago
FixSecurityService

Retail store connections are reachable only by their own org's commerce settings managers

The retail provider-config handlers on CommerceMarketController resolved the session's org and then used whatever market and config uid the path named. Update, ...

Kamo·1w ago
FixSecurityService

The System User acts only inside the organization it was entered into

There is one System User for the whole platform. Platform operators, and support staff holding a grant scoped to a single ticket's organization, enter a tenant ...

Kamo·1w ago
FixSecurityService

Only an org's owner, its CONFIGURE_SYSTEM members or active god mode can change its settings

PUT /api/security/org/{id} took no request at all. ResourceServerConfig permits every request and APIService relays /api/security/**, so one anonymous request c...

Kamo·1w ago
FixSecurityService

An OAuth app save keeps its client secret unless a new one is typed; owners' credentials stay out of org JSON

PUT /api/oauth-config/{id} stored whatever arrived under clientSecret. Responses mask the secret, and the edit form sends a blank back while promising "Leave bl...

Kamo·1w ago
TestSecurityService

A search term reads the lead's email

Walks the grid specification's LIKE branches on the Hibernate this service runs (the HQL rendering leaves function arguments out, so it cannot show which column...

Kamo·1w ago
FixSecurityService

Stop GET /org/{id} shipping the GoDaddy credentials, and lock it to this service's mapper

The fix is in kamo-shared-library 096feaa1: Organization.godaddyApiKey and godaddyApiSecret are now @JsonIgnore. That change reaches production only when a serv...

Kamo·1w ago
FeatureSecurityService

Lifestyle logo uploads, config.json keys, and the LIFESTYLE watermark

The lifestyle logo is a fourth logo per brand (company and white-label), the decorative rendition the background watermark now draws by default. Its fallback is...

Kamo·1w ago
FeatureSecurityService

An imported lead is recorded as imported

LeadImportController created every row with the two-argument createLead, so a lead's history said source API with nobody acting, exactly like one sent in throug...

Kamo·1w ago
September 16, 2026
FixSecurityService

Retry public reads the database aborted with 40001

Every DDL bumps the YSQL catalog version, and a transaction that began on the old one fails with "catalog snapshot ... invalidated: MISMATCHED_SCHEMA" (SQLSTATE...

Kamo·1w ago
OtherSecurityService

Release idle Hikari connections now that YSQL pooling is shared

The connection manager no longer pins sessions **************** so idle app connections no longer each hold a database backend. Keep the pool maximum, but stop ...

Kamo·1w ago
FixSecurityService

Take kamo-meet and kamo-analytics off the public changelog

Both names leave changelog.public-projects. Every public read goes through that one list, so the marketing site's /changelog stops showing them everywhere at on...

Kamo·1w ago
FeatureSecurityService

The Email Campaigns widget arrives on for everyone who can open the campaigns

EMAIL_CAMPAIGNS_WIDGET and its ADDED, OPTIONAL and MOVABLE policies seed from VIEW_BULK_EMAIL on the boot that introduces them, so the pane lands on the launchp...

Kamo·1w ago
September 13, 2026
FeatureSecurityService

Lead opt-out panel passes personAsked to the ledger

The lead page's opt-out update takes an optional personAsked flag and hands it to the ledger, which now refuses to lift a person's own unsubscribe, complaint or...

Kamo·2w ago
FeatureSecurityService

The organizations each member created, on the member lists

GET **************** and /team-members-contractors now carry createdOrgs per person: the names of the organizations they own (orgs.user_id_owner, set once by PO...

Kamo·2w ago
FeatureSecurityService

An organization's and a member's own page transition

The page transition is now chosen at three levels, resolved member, then organization, then platform — for the choice of transition and, one transition at a tim...

Kamo·2w ago
September 12, 2026
FeatureSecurityService

Tune each page transition, tile size and colour to start

GET and PUT /api/security/page-transition answer options for every catalogue id, normalised from PAGE_TRANSITION_OPTIONS: a missing, unreadable or out-of-range ...

Kamo·2w ago
FeatureSecurityService

Every tab reads the page transition, and an operator chooses it

GET /api/security/page-transition answers any signed-in session, since every tab needs it to uncover a page; an unset or unknown value reads as TILE_DISSOLVE. T...

Kamo·2w ago
FixSecurityService

The id resolver never hands a campaign an address the member can't read

Resolving lead ids read each address through the lead masking DTO and skipped only blank ones. Masking now obfuscates instead of blanking ("s*****@gmail.com"), ...

Kamo·2w ago
FeatureSecurityService

A lead's opt-out change refreshes open screens live

The ledger here tells OptOutChangePublisher after the change commits, which publishes rt.org.{orgId}.email-opt-outs on core NATS (this service's JetStream strea...

Kamo·2w ago
FeatureSecurityService

Issue personal single-use codes from a template promotion

The kamocrm.com site hunt hands each solver a code of their own, and only the first N solvers ever get one. A shared code could not do that: the first solver to...

Kamo·2w ago
FixSecurityService

A new organization's folder holds none of the platform's backgrounds, stylesheet or config

Provisioning copied the whole base theme into every new organization's folder, KamoCRM's three sign-in photographs included. They sat at img/bg/1-3.webp under t...

Kamo·2w ago
FixSecurityService

A god account is shown every organization, wherever it is signed in

GET /org/all-networks - the list behind /network - was gated on the SYSTEM_USER platform right alone, and platform rights resolve only in a top-level-organizati...

Kamo·2w ago
FeatureSecurityService

See and change a lead's email opt-out from the lead

A member working a lead can now see whether that person may be emailed, and change it, without the org-wide opt-out settings list. GET **************** answers...

Kamo·2w ago
TestSecurityService

MANAGE_OUTBOUND_EMAIL_HOSTS is enforced in EmailService

PlatformOutboundHostsController checks it through SessionPlatformFacts and the shared PlatformRightsResolver, so it is listed with the rights enforced elsewhere...

Kamo·2w ago
September 11, 2026
FixSecurityService

An echo of the censored English is not a translation

translatedLocales compared each translation with the English title as stored. The translator is given the censored title (ChangelogSanitizationService masks sec...

Kamo·2w ago
FixSecurityService

The General tab counts what the Organizations tab calls Active

6c8d789 moved the platform overview's organization count onto findAllLive(), which also drops orgs created by synthetic (is_fake) accounts — so the General tab ...

Kamo·2w ago
FeatureSecurityService

Say which locales each entry is really translated into

The marketing site's sitemap now lists every language version of every entry, and each entry page names the others as its hreflang alternates. A translation row...

Kamo·2w ago
FeatureSecurityService

Void an organization, and let no way in reach a voided one

Platform -> Configuration -> Organizations can now void an organization. The void is orgs.is_active = FALSE; this commit adds the action and makes every way INT...

Kamo·2w ago
FeatureSecurityService

Give every public entry an address, and page the list on the server

The public changelog served entries with no identifier, so the marketing site could neither link to one nor list them in a sitemap. Each entry now carries a slu...

Kamo·2w ago
FeatureSecurityService

Bake the careers site's logo overlay into config.json

kamo-careers paints the org's logo in its header and has no OrgContext; it reads the theme config.json on the server, the same file login, register and apps tak...

Kamo·2w ago
September 10, 2026
FixSecurityService

Quote and borrower-portal links only name a live domain

QuoteEmailClient settled for any active domain, verified or not, so an org still setting up its white-label domain had quote links mailed to sign.<that domain>....

Kamo·2w ago
FixSecurityService

An organization's .svg names show its own art, not the platform's

A new organization's folder is seeded from the base theme, so it starts out with KamoCRM's art under img/logo-full.svg and favicon/favicon.svg. An organization ...

Kamo·2w ago
FeatureSecurityService

Say when the desk changes

Granting or revoking Exec2Exec Access now publishes exec2exec.desk.changed, so MediaService can put an executive on every chat — or take them off — as the toggl...

Kamo·2w ago
FeatureSecurityService

Store the Welcome Message

The greeting the platform sends first over Exec2Exec, on the platform config singleton where every other platform-wide setting already lives. Two new endpoints...

Kamo·2w ago
September 9, 2026
FixSecurityService

An org without the app must not accrue achievements either

The award gate asked for VIEW_ACHIEVEMENTS and stopped there. Rights are not entitlement-filtered, so that right stays granted — and keeps answering true — in a...

Kamo·2w ago

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing