KamoCRM

Live Change Log

Every feature, fix and improvement, posted as it ships. Nothing is held back for a launch.

15,120
Total Changes
5,169
Features
4,935
Fixes
30
Projects
Filter by project
All Projects15,120AIService197APIService161BillingService143ConversionService107DaemonService129DocsService215ESigService88EmailService518InitializerService318KBService105KlusterServices697MCPGatewayService85MediaService546RAGService71SecurityService1,658TranslateService55VOIPService205VectorService11kamo-apps25kamo-asterisk-support24kamo-capcha17kamo-capcha-widget4kamo-internal6,937kamo-login330kamo-marketing625kamo-nowww20kamo-register213kamo-shared-library1,455kamo-signer-monorepo53kamolos108
Filter by type
All TypesBuild11CI523Chore738Docs2,167Feature5,169Fix4,935Other986Performance157Refactor274Revert23Style42Test94Upgrade1
September 23, 2026
FeatureEmailService

A lead who writes in is named by the correspondent resolver

The mailbox list headed a lead's message with the part of their address before the @ ("jlrivera1984") when their mail client sent no display name, although the ...

Kamo·6d ago
FeatureEmailService

A lead who writes in is named by the correspondent resolver

The mailbox list headed a lead's message with the part of their address before the @ ("rodarisdolgovanton") when their mail client sent no display name, althoug...

Kamo·6d ago
Fixkamo-internal

The last step no longer hangs on "Loading..." after it is saved

Saving or skipping Compliance, the ninth and last Getting Started step, left it on "Loading..." with "Save & continue" greyed out, under the banner saying the o...

Kamo·6d ago
FixKlusterServices

Only the platform reaches the database's and NATS's admin ports

YugabyteDB and NATS run on k1m1's host network, so every pod in every namespace could open every port they listen on. The client ports authenticate (YSQL :5433 ...

Kamo·6d ago
FixKlusterServices

NATS refuses anonymous clients — no_auth_user is gone

Second half of 926986d. Every client now presents the kamo_svc login: the Java services through the shared library's NatsConfig (NATS_USERNAME / NATS_PASSWORD f...

Kamo·6d ago
FixKlusterServices

Three RBAC grants no provision had ever needed

Nothing had ever been provisioned, so every grant past the namespace was untested. Each of these refused at exactly the point the previous fix unblocked. `patc...

Kamo·6d ago
Fixkamo-internal

The official title and membership status are read-only on your own Position card

They join the department and job title under positionRights: a member sees all four on their own Position card, but only a MANAGE_MEMBER_SECURITY holder (or an ...

Kamo·6d ago
FixSecurityService

A member's official title and status need member security too, on their own record

Department and job title already needed MANAGE_MEMBER_SECURITY (or an open god window) on /member-security, your own record included. The rest of the Position c...

Kamo·6d ago
FixSecurityService

CommerceMarketController's retail sub-resources are org-scoped

CommerceMarketController's get-one/update/delete handlers under /retail/... called RetailService methods that took no orgId (bare findById/deleteById) - a same-...

Kamo·6d ago
Fixkamo-internal

Kamo-internal presents the NATS login

NATS mapped every credential-less connection to the KAMO account (no_auth_user), and it listens on the host network of k1m1 — so any pod, the desktop VM or a ma...

Kamo·6d ago
FixSecurityService

Drop 4 newly-guarded handlers from the unguarded-endpoints ratchet

**************** caught the previous commit: **************** and **************** now resolve a session (getCachedOrganizationId, in each handler's own body), ...

Kamo·6d ago
Fixkamo-shared-library

Org-scope RetailService and ****************

Every get/update/delete-by-uid handler under CommerceMarketController's retail sub-resources (categories, brands, attributes/values, images, variants, tags, rev...

Kamo·6d ago
FixSecurityService

Scope roles, member access and profile writes to the caller's org

Five gaps let a signed-in member reach outside their own organization, or reach a colleague's account, with no right check: - **************** resolved no sess...

Kamo·6d ago
Fixkamo-shared-library

UpdateMemberAccess rejects an editor and target in different orgs

**************** compared only security levels and the editor's owner flag, never the two members' organizations. Its one caller today (SecurityService's Member...

Kamo·6d ago
PerformanceSecurityService

An entry page reads three rows, not the whole public changelog

pg_stat_statements put the public changelog's single-entry reads at the top of the database by a distance: the slug lookup and the two neighbour lookups ran ~90...

Kamo·6d ago
FixKBService

KBService presents the NATS login

NATS mapped every credential-less connection to the KAMO account (no_auth_user), and it listens on the host network of k1m1 — so any pod, the desktop VM or a ma...

Kamo·6d ago
FixRAGService

RAGService presents the NATS login

NATS mapped every credential-less connection to the KAMO account (no_auth_user), and it listens on the host network of k1m1 — so any pod, the desktop VM or a ma...

Kamo·6d ago
FixKlusterServices

NATS clients authenticate — first half of retiring no_auth_user

NATS runs on the host network of k1m1 and listens on 0.0.0.0, and its config mapped every credential-less connection to the KAMO account (no_auth_user: anon). S...

Kamo·6d ago
FixSecurityService

Forward the actor when relaying a commission line

addLine/updateLine relayed memberId (normalized to Long in 789c544) but never who was making the call — unlike openDraft, send, voidLine and every Stripe-config...

Kamo·6d ago
FixKlusterServices

Only the platform can reach the session Redis

The `kamo` Redis holds every *** session and OTK and has no password. Nothing restricted who could connect to it: from a pod in the `desktop` namespace (where t...

Kamo·6d ago
Fixkamo-internal

The imaging proxy passes MediaService's download and sandbox headers through

MediaService now serves any attachment outside its safe raster/audio/video list (SVG, HTML, PDF…) with Content-Disposition: attachment, X-Content-Type-Options: ...

Kamo·6d ago
FixVectorService

Require a valid *** session on the unauthenticated pipeline endpoints

POST /convert-vector and WS /ws/pipeline took no auth at all — 4820f44 capped upload size and conversion concurrency but left the actual hole open pending a dec...

Kamo·6d ago
FixMediaService

Break a circular bean dependency the STOMP live-session guard introduced

d47b471's SessionAccessGuard field on WebSocketConfig crash-looped every pod: Spring must fully construct WebSocketConfig (a **************** every @Autowired f...

Kamo·6d ago
FixBillingService

Only an organization's owner may change who pays for mailboxes or extensions

**************** and **************** had no authorization check at all — any member of the organization, not only its owner, could move the whole organization'...

Kamo·6d ago
FixMediaService

Guard STOMP SUBSCRIBE to a session's live messages and WebRTC signaling

/topic/chat/session/{guid} and /topic/webrtc/session/{guid} were not guarded at all: any authenticated socket could SUBSCRIBE to another session's live chat mes...

Kamo·6d ago
Fixkamo-internal

Drop the process-wide TLS verification bypass

NODE_TLS_REJECT_UNAUTHORIZED: "0" in k8s/configmap.yaml made every server-side outbound TLS call in this process — to any host, for any purpose, for as long as ...

Kamo·6d ago
Fixkamo-internal

Stop logging session tokens, cookies and message content

A grep for the shape of two known offenders (chat message text and chat-list previews going to console.log) turned up a much wider pattern across the session/au...

Kamo·6d ago
Fixkamo-internal

Reject unauthenticated uploads before the body is spooled

The chat attachment upload, the support bug-report screenshot upload, the meet background upload and the two ConversionService image-resize proxies all called b...

Kamo·6d ago
FixSecurityService

Forward subjectMemberId and role so TimecardService can verify punch ownership

**************** resolved the caller's role against a CLIENT-SUPPLIED subjectMemberId (resolveRole -> EMPLOYEE whenever actor==subject) but never forwarded that...

Kamo·6d ago
FixMediaService

Chat attachment uploads authenticate before the body is spooled

POST /sessions/{guid}/attachments bound its parts as a @RequestParam MultipartFile[] method parameter. Spring resolves method parameters before a controller met...

Kamo·6d ago
FixDocsService

DocsService is no longer published directly at docs-api.kamocrm.com

The docs-api-ingress IngressRoute sent the internet straight to DocsService, around the api gateway (and its identity-header stripping). Nothing used the host: ...

Kamo·6d ago
FixConversionService

ConversionService is no longer published to the internet

The conversion-api.kamocrm.com IngressRoute sent anyone on the internet to this service, where several endpoints (/image/resize-bg, /favicon/generate, /convert-...

Kamo·6d ago
FixMediaService

Strip client-supplied identity headers at the media.* edge

media-route (HostRegexp ^media[.].+$) carried only media-websocket-upgrade, so a caller hitting media.<domain> directly could set X-Org-Id, X-Member-Id, X-Publi...

Kamo·6d ago
FixMediaService

Presence bulk reads and the stale-presence sweep stop using Redis KEYS

getBulkPresence/getBulkLastSeen ran KEYS PRESENCE:*/PRESENCE_LAST_SEEN:* on every call - hit on every presence-socket mount and tab focus - and the 30s sweep ra...

Kamo·6d ago
FixConversionService

Auth on the endpoints that can take it now, ffmpeg/Batik hardening on the rest

ResourceServerConfig permits every request (this service is reachable anonymously at conversion-api.kamocrm.com), and none of ImageOpsController's or Conversion...

Kamo·6d ago
FixAPIService

Give the gateway a memory request and limit

The deployment had no resources: block at all. No request, so the scheduler could not reason about this pod's footprint; no limit, so nothing capped the JVM's -...

Kamo·6d ago
FixAPIService

Forward commission Stripe Connect webhooks, which reached nothing at all

CommissionService registers **************** directly with Stripe (OrgStripeSetupService), but no /api/commissions/** forward existed anywhere in this gateway -...

Kamo·6d ago
FixAPIService

Carve out VOIPService's internal SMS-template API, and never forward a client's own X-Internal-Auth

Two related gaps in the same trust boundary. /api/voip/sms/templates/** was forwarded wholesale by the /api/voip/** wildcard. VOIPService's InternalAuthFilter ...

Kamo·6d ago
FixMediaService

Stop logging STOMP frame headers/payloads and /ws request headers

Two leftover debug-logging spots on the WebSocket path: - WebSocketConfig's inbound channel interceptor logged every STOMP frame at INFO, including accessor....

Kamo·6d ago
FixAPIService

Derive X-Real-IP from the right-most hop, not the client's own

forward() set the outgoing X-Real-IP to X-Forwarded-For.split(",")[0] -- the LEFT-most hop, which is the one part of that header a client controls outright: a r...

Kamo·6d ago
FixAPIService

Bound upstream calls with a connect and a read timeout

Both RestTemplate beans were built from a bare JdkClientHttpRequestFactory with no timeout at all. One upstream that accepts the connection and then never answe...

Kamo·6d ago
FixAPIService

Stop logging session tokens, OTKs and auth headers on every request

forward() printed the entire copied-header map on every single call -- System.out.println("APIService: copied headers: " + outHeaders) -- which serializes X-***...

Kamo·6d ago
FixConversionService

Internal-auth secret comparisons are constant-time and fail closed

TranscriptionController, RecordingIngestController and RecordingProcessController all compared X-Internal-Auth with String.equals (a timing oracle on a shared s...

Kamo·6d ago
FixMediaService

Imaging proxy forces a download for anything that isn't a safe raster or a stream

GET/HEAD **************** always answered with the client-declared Content-Type from upload, no Content-Disposition, no X-Content-Type-Options and no CSP. ChatA...

Kamo·6d ago
FixMediaService

The meet-provider OAuth result page can no longer break out of its own script tag

MeetProviderController's GET /oauth/callback is sessionless and reflects the provider's error_description into an inline <script> block. The old jsString() only...

Kamo·6d ago
Fixkamo-internal

The learner media route's HEAD answers instead of hanging

useAttachmentSource probes with a HEAD after a media element fails, to tell a file that is gone from a session that lapsed. The route awaited response.body.canc...

Kamo·6d ago
FixESigService

The internal envelope API fails closed and compares its secret in constant time

**************** used String.equals against X-Internal-Auth (a timing side channel on a shared secret) and, when esig.internal-auth-secret was unset, logged a w...

Kamo·6d ago
FixESigService

The staff envelope API now requires a document right, and HR envelopes need an HR one

EsignEnvelopeController's **************** checked org membership only — no document right, no clearance, nothing context-specific. Any authenticated staff memb...

Kamo·6d ago
FixESigService

Thread orgId through every template handler, EDIT_DOCUMENTS on writes

ESignTemplateService's signer/design handlers (getSigners, upsertSigners, reorderSigners, deleteSigner, saveDesign, getLatestDesign, listDesignVersions, getDesi...

Kamo·6d ago
Fixkamo-shared-library

RegisterExistingDocument checks the dat's org, and a template can be found by imgId within one

Two org-scoping gaps the esig/imaging audit found, both in shared entry points other services build on: - **************** (the conversion service's dedup-skip...

Kamo·6d ago

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing