A lead who writes in is named by the correspondent resolver
The mailbox list headed a lead's message with the part of their address before the @ ("jlrivera1984") when their mail client sent no display name, although the ...
A lead who writes in is named by the correspondent resolver
The mailbox list headed a lead's message with the part of their address before the @ ("rodarisdolgovanton") when their mail client sent no display name, althoug...
The last step no longer hangs on "Loading..." after it is saved
Saving or skipping Compliance, the ninth and last Getting Started step, left it on "Loading..." with "Save & continue" greyed out, under the banner saying the o...
Only the platform reaches the database's and NATS's admin ports
YugabyteDB and NATS run on k1m1's host network, so every pod in every namespace could open every port they listen on. The client ports authenticate (YSQL :5433 ...
NATS refuses anonymous clients — no_auth_user is gone
Second half of 926986d. Every client now presents the kamo_svc login: the Java services through the shared library's NatsConfig (NATS_USERNAME / NATS_PASSWORD f...
Three RBAC grants no provision had ever needed
Nothing had ever been provisioned, so every grant past the namespace was untested. Each of these refused at exactly the point the previous fix unblocked. `patc...
The official title and membership status are read-only on your own Position card
They join the department and job title under positionRights: a member sees all four on their own Position card, but only a MANAGE_MEMBER_SECURITY holder (or an ...
A member's official title and status need member security too, on their own record
Department and job title already needed MANAGE_MEMBER_SECURITY (or an open god window) on /member-security, your own record included. The rest of the Position c...
CommerceMarketController's retail sub-resources are org-scoped
CommerceMarketController's get-one/update/delete handlers under /retail/... called RetailService methods that took no orgId (bare findById/deleteById) - a same-...
Kamo-internal presents the NATS login
NATS mapped every credential-less connection to the KAMO account (no_auth_user), and it listens on the host network of k1m1 — so any pod, the desktop VM or a ma...
Drop 4 newly-guarded handlers from the unguarded-endpoints ratchet
**************** caught the previous commit: **************** and **************** now resolve a session (getCachedOrganizationId, in each handler's own body), ...
Org-scope RetailService and ****************
Every get/update/delete-by-uid handler under CommerceMarketController's retail sub-resources (categories, brands, attributes/values, images, variants, tags, rev...
Scope roles, member access and profile writes to the caller's org
Five gaps let a signed-in member reach outside their own organization, or reach a colleague's account, with no right check: - **************** resolved no sess...
UpdateMemberAccess rejects an editor and target in different orgs
**************** compared only security levels and the editor's owner flag, never the two members' organizations. Its one caller today (SecurityService's Member...
An entry page reads three rows, not the whole public changelog
pg_stat_statements put the public changelog's single-entry reads at the top of the database by a distance: the slug lookup and the two neighbour lookups ran ~90...
KBService presents the NATS login
NATS mapped every credential-less connection to the KAMO account (no_auth_user), and it listens on the host network of k1m1 — so any pod, the desktop VM or a ma...
RAGService presents the NATS login
NATS mapped every credential-less connection to the KAMO account (no_auth_user), and it listens on the host network of k1m1 — so any pod, the desktop VM or a ma...
NATS clients authenticate — first half of retiring no_auth_user
NATS runs on the host network of k1m1 and listens on 0.0.0.0, and its config mapped every credential-less connection to the KAMO account (no_auth_user: anon). S...
Forward the actor when relaying a commission line
addLine/updateLine relayed memberId (normalized to Long in 789c544) but never who was making the call — unlike openDraft, send, voidLine and every Stripe-config...
Only the platform can reach the session Redis
The `kamo` Redis holds every *** session and OTK and has no password. Nothing restricted who could connect to it: from a pod in the `desktop` namespace (where t...
The imaging proxy passes MediaService's download and sandbox headers through
MediaService now serves any attachment outside its safe raster/audio/video list (SVG, HTML, PDF…) with Content-Disposition: attachment, X-Content-Type-Options: ...
Require a valid *** session on the unauthenticated pipeline endpoints
POST /convert-vector and WS /ws/pipeline took no auth at all — 4820f44 capped upload size and conversion concurrency but left the actual hole open pending a dec...
Break a circular bean dependency the STOMP live-session guard introduced
d47b471's SessionAccessGuard field on WebSocketConfig crash-looped every pod: Spring must fully construct WebSocketConfig (a **************** every @Autowired f...
Only an organization's owner may change who pays for mailboxes or extensions
**************** and **************** had no authorization check at all — any member of the organization, not only its owner, could move the whole organization'...
Guard STOMP SUBSCRIBE to a session's live messages and WebRTC signaling
/topic/chat/session/{guid} and /topic/webrtc/session/{guid} were not guarded at all: any authenticated socket could SUBSCRIBE to another session's live chat mes...
Drop the process-wide TLS verification bypass
NODE_TLS_REJECT_UNAUTHORIZED: "0" in k8s/configmap.yaml made every server-side outbound TLS call in this process — to any host, for any purpose, for as long as ...
Stop logging session tokens, cookies and message content
A grep for the shape of two known offenders (chat message text and chat-list previews going to console.log) turned up a much wider pattern across the session/au...
Reject unauthenticated uploads before the body is spooled
The chat attachment upload, the support bug-report screenshot upload, the meet background upload and the two ConversionService image-resize proxies all called b...
Forward subjectMemberId and role so TimecardService can verify punch ownership
**************** resolved the caller's role against a CLIENT-SUPPLIED subjectMemberId (resolveRole -> EMPLOYEE whenever actor==subject) but never forwarded that...
Chat attachment uploads authenticate before the body is spooled
POST /sessions/{guid}/attachments bound its parts as a @RequestParam MultipartFile[] method parameter. Spring resolves method parameters before a controller met...
DocsService is no longer published directly at docs-api.kamocrm.com
The docs-api-ingress IngressRoute sent the internet straight to DocsService, around the api gateway (and its identity-header stripping). Nothing used the host: ...
ConversionService is no longer published to the internet
The conversion-api.kamocrm.com IngressRoute sent anyone on the internet to this service, where several endpoints (/image/resize-bg, /favicon/generate, /convert-...
Strip client-supplied identity headers at the media.* edge
media-route (HostRegexp ^media[.].+$) carried only media-websocket-upgrade, so a caller hitting media.<domain> directly could set X-Org-Id, X-Member-Id, X-Publi...
Presence bulk reads and the stale-presence sweep stop using Redis KEYS
getBulkPresence/getBulkLastSeen ran KEYS PRESENCE:*/PRESENCE_LAST_SEEN:* on every call - hit on every presence-socket mount and tab focus - and the 30s sweep ra...
Auth on the endpoints that can take it now, ffmpeg/Batik hardening on the rest
ResourceServerConfig permits every request (this service is reachable anonymously at conversion-api.kamocrm.com), and none of ImageOpsController's or Conversion...
Give the gateway a memory request and limit
The deployment had no resources: block at all. No request, so the scheduler could not reason about this pod's footprint; no limit, so nothing capped the JVM's -...
Forward commission Stripe Connect webhooks, which reached nothing at all
CommissionService registers **************** directly with Stripe (OrgStripeSetupService), but no /api/commissions/** forward existed anywhere in this gateway -...
Carve out VOIPService's internal SMS-template API, and never forward a client's own X-Internal-Auth
Two related gaps in the same trust boundary. /api/voip/sms/templates/** was forwarded wholesale by the /api/voip/** wildcard. VOIPService's InternalAuthFilter ...
Stop logging STOMP frame headers/payloads and /ws request headers
Two leftover debug-logging spots on the WebSocket path: - WebSocketConfig's inbound channel interceptor logged every STOMP frame at INFO, including accessor....
Derive X-Real-IP from the right-most hop, not the client's own
forward() set the outgoing X-Real-IP to X-Forwarded-For.split(",")[0] -- the LEFT-most hop, which is the one part of that header a client controls outright: a r...
Bound upstream calls with a connect and a read timeout
Both RestTemplate beans were built from a bare JdkClientHttpRequestFactory with no timeout at all. One upstream that accepts the connection and then never answe...
Stop logging session tokens, OTKs and auth headers on every request
forward() printed the entire copied-header map on every single call -- System.out.println("APIService: copied headers: " + outHeaders) -- which serializes X-***...
Internal-auth secret comparisons are constant-time and fail closed
TranscriptionController, RecordingIngestController and RecordingProcessController all compared X-Internal-Auth with String.equals (a timing oracle on a shared s...
Imaging proxy forces a download for anything that isn't a safe raster or a stream
GET/HEAD **************** always answered with the client-declared Content-Type from upload, no Content-Disposition, no X-Content-Type-Options and no CSP. ChatA...
The meet-provider OAuth result page can no longer break out of its own script tag
MeetProviderController's GET /oauth/callback is sessionless and reflects the provider's error_description into an inline <script> block. The old jsString() only...
The learner media route's HEAD answers instead of hanging
useAttachmentSource probes with a HEAD after a media element fails, to tell a file that is gone from a session that lapsed. The route awaited response.body.canc...
The internal envelope API fails closed and compares its secret in constant time
**************** used String.equals against X-Internal-Auth (a timing side channel on a shared secret) and, when esig.internal-auth-secret was unset, logged a w...
The staff envelope API now requires a document right, and HR envelopes need an HR one
EsignEnvelopeController's **************** checked org membership only — no document right, no clearance, nothing context-specific. Any authenticated staff memb...
Thread orgId through every template handler, EDIT_DOCUMENTS on writes
ESignTemplateService's signer/design handlers (getSigners, upsertSigners, reorderSigners, deleteSigner, saveDesign, getLatestDesign, listDesignVersions, getDesi...
RegisterExistingDocument checks the dat's org, and a template can be found by imgId within one
Two org-scoping gaps the esig/imaging audit found, both in shared entry points other services build on: - **************** (the conversion service's dedup-skip...
Like what you see shipping?
All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.
