The forgot-password hint is the account's address, whatever it is
d7ff5ed called the address on the user account "personal" everywhere: in the 409's message, the response field and the class. It is not always personal. An admi...
Kamouniverse.com redirect was losing to the www.* catch-all
www.kamouniverse.com was served by the kamocrm.com marketing app instead of redirecting: kamo-marketing-route's HostRegexp(\`^www[.].+\$\`) at priority 24 match...
The login greeter was counting as a member using the computer
rdp_sessions() collected every Xorg process with a display argument. The image installs lightdm and lightdm-gtk-greeter, so lightdm runs its own Xorg on :0 on e...
Catch dead domains and dead mailboxes the checks let through
Campaign 8781b848 ended with 667 bounces and 1,258 failures. Three gaps in the existing eligibility engine let them through: - DomainMailCheck asked A and AAAA...
A stale resume_offset would hibernate into the wrong place
resume_configured() checked that `resume=` and `resume_offset=` were present on the running kernel's command line. Present, not correct — and the difference is ...
Root could not read a member's idle time, so nothing ever slept
The first computer reported its idle time as 13.9, then 29.2, then 14.4 seconds over three minutes while nobody was touching it. That is not a person — it is a ...
The swap file was smaller than the check that measures it
With the restart landing, the first computer came up with resumeConfigured true and stopped on the next precondition — which turns out to be unsatisfiable by co...
A computer could never restart into being able to sleep
The first real Hosted Computer reached AWAKE and then stayed awake forever. Hibernation reported resumeConfigured: false, IdleWatcher only arms when readiness i...
Send the lead-filter query params the backend actually parses
**************** reads marketIds/vendorIds/ vendorProductIds/states as one comma-separated param each (splitList()), but campaignAudienceApi's appendLeadFilter(...
Wait long enough for a computer to finish waking
WAKE_TIMEOUT_MS was 180_000 and sat exactly on top of the VM's readiness probe, whose initialDelaySeconds was 180 and which KubeVirt renders as 190. A computer ...
Start probing at 15s, not 190 — nothing could open on its first wake
A woken computer is only reachable once its Service has endpoints, and that happens when the readiness probe on 3389 first passes. initialDelaySeconds was 180, ...
Xorg may not start from a remote session, so no computer opened
Guacamole connected, authenticated, and was hung up on: guacd: Security mode: Negotiate (ANY) guacd: Loading keymap "en-us-qwerty" guacd: RDP serve...
The nav opens a computer, it does not ask for a password
Being signed in to Kamo is the authentication that matters; asking again at the door of your own machine is a password prompt for its own sake. ComputeService m...
Traefik could not see the gateway, and it served at the wrong path
Opening a computer landed on the redirect service's fallback page — "the request reached the fallback page instead of being redirected. Check the Host header." ...
Opening a computer with no login yet asks for the password
Clicking a computer opened a browser tab that closed again, and said nothing. openHostedComputer opens its tab synchronously inside the click, because a popup ...
Let auto-cert mirror the gateway certificate into this namespace
Listing computers.kamocrm.com for issuance is only half of it. Traefik requires a TLS secret in the IngressRoute's OWN namespace, so the cert is issued in `kamo...
A computer that has never restarted can never sleep
prepare-sleep writes the swap file and the resume wiring, then reports readiness — and readiness reads `resume=` from /proc/cmdline, which the kernel fixed at b...
Reinstall grub after virt-resize, or the guest boots to a rescue prompt
virt-resize renumbers partitions. Canonical's image is laid out p14 (BIOS boot), p15 (ESP), p16 (/boot) and then p1 (root) physically last, and virt-resize rewr...
Only the platform namespaces can call ConversionService
The public route is gone (28ba91b), but inside the cluster any pod could still reach this service, and several endpoints take no credential because none of its ...
Gift cards take the Discounts tab's pricing rights
Listing gift cards, issuing one and editing one (including its balance, which the shared library sets again as of the companion kamo-shared-library commit) chec...
A gift card's balance is editable again, by whoever may manage pricing
19505faf stopped updateGiftCard from reading currentBalance so a member of one org could not rewrite another org's card by uid. The org-scoped lookup already cl...
The golden disk has to be RAW, or nothing boots and nothing says so
The job wrote the compressed qcow2 the build produces straight into the golden claim. KubeVirt attaches a Filesystem-PVC disk with <driver type='raw'> — always,...
The last step no longer hangs on "Loading..." after it is saved
Saving or skipping Compliance, the ninth and last Getting Started step, left it on "Loading..." with "Save & continue" greyed out, under the banner saying the o...
Only the platform reaches the database's and NATS's admin ports
YugabyteDB and NATS run on k1m1's host network, so every pod in every namespace could open every port they listen on. The client ports authenticate (YSQL :5433 ...
NATS refuses anonymous clients — no_auth_user is gone
Second half of 926986d. Every client now presents the kamo_svc login: the Java services through the shared library's NatsConfig (NATS_USERNAME / NATS_PASSWORD f...
Three RBAC grants no provision had ever needed
Nothing had ever been provisioned, so every grant past the namespace was untested. Each of these refused at exactly the point the previous fix unblocked. `patc...
The official title and membership status are read-only on your own Position card
They join the department and job title under positionRights: a member sees all four on their own Position card, but only a MANAGE_MEMBER_SECURITY holder (or an ...
A member's official title and status need member security too, on their own record
Department and job title already needed MANAGE_MEMBER_SECURITY (or an open god window) on /member-security, your own record included. The rest of the Position c...
CommerceMarketController's retail sub-resources are org-scoped
CommerceMarketController's get-one/update/delete handlers under /retail/... called RetailService methods that took no orgId (bare findById/deleteById) - a same-...
Kamo-internal presents the NATS login
NATS mapped every credential-less connection to the KAMO account (no_auth_user), and it listens on the host network of k1m1 — so any pod, the desktop VM or a ma...
Drop 4 newly-guarded handlers from the unguarded-endpoints ratchet
**************** caught the previous commit: **************** and **************** now resolve a session (getCachedOrganizationId, in each handler's own body), ...
Org-scope RetailService and ****************
Every get/update/delete-by-uid handler under CommerceMarketController's retail sub-resources (categories, brands, attributes/values, images, variants, tags, rev...
Scope roles, member access and profile writes to the caller's org
Five gaps let a signed-in member reach outside their own organization, or reach a colleague's account, with no right check: - **************** resolved no sess...
UpdateMemberAccess rejects an editor and target in different orgs
**************** compared only security levels and the editor's owner flag, never the two members' organizations. Its one caller today (SecurityService's Member...
KBService presents the NATS login
NATS mapped every credential-less connection to the KAMO account (no_auth_user), and it listens on the host network of k1m1 — so any pod, the desktop VM or a ma...
RAGService presents the NATS login
NATS mapped every credential-less connection to the KAMO account (no_auth_user), and it listens on the host network of k1m1 — so any pod, the desktop VM or a ma...
NATS clients authenticate — first half of retiring no_auth_user
NATS runs on the host network of k1m1 and listens on 0.0.0.0, and its config mapped every credential-less connection to the KAMO account (no_auth_user: anon). S...
Forward the actor when relaying a commission line
addLine/updateLine relayed memberId (normalized to Long in 789c544) but never who was making the call — unlike openDraft, send, voidLine and every Stripe-config...
Only the platform can reach the session Redis
The `kamo` Redis holds every *** session and OTK and has no password. Nothing restricted who could connect to it: from a pod in the `desktop` namespace (where t...
The imaging proxy passes MediaService's download and sandbox headers through
MediaService now serves any attachment outside its safe raster/audio/video list (SVG, HTML, PDF…) with Content-Disposition: attachment, X-Content-Type-Options: ...
Require a valid *** session on the unauthenticated pipeline endpoints
POST /convert-vector and WS /ws/pipeline took no auth at all — 4820f44 capped upload size and conversion concurrency but left the actual hole open pending a dec...
Break a circular bean dependency the STOMP live-session guard introduced
d47b471's SessionAccessGuard field on WebSocketConfig crash-looped every pod: Spring must fully construct WebSocketConfig (a **************** every @Autowired f...
Only an organization's owner may change who pays for mailboxes or extensions
**************** and **************** had no authorization check at all — any member of the organization, not only its owner, could move the whole organization'...
Guard STOMP SUBSCRIBE to a session's live messages and WebRTC signaling
/topic/chat/session/{guid} and /topic/webrtc/session/{guid} were not guarded at all: any authenticated socket could SUBSCRIBE to another session's live chat mes...
Drop the process-wide TLS verification bypass
NODE_TLS_REJECT_UNAUTHORIZED: "0" in k8s/configmap.yaml made every server-side outbound TLS call in this process — to any host, for any purpose, for as long as ...
Stop logging session tokens, cookies and message content
A grep for the shape of two known offenders (chat message text and chat-list previews going to console.log) turned up a much wider pattern across the session/au...
Reject unauthenticated uploads before the body is spooled
The chat attachment upload, the support bug-report screenshot upload, the meet background upload and the two ConversionService image-resize proxies all called b...
Forward subjectMemberId and role so TimecardService can verify punch ownership
**************** resolved the caller's role against a CLIENT-SUPPLIED subjectMemberId (resolveRole -> EMPLOYEE whenever actor==subject) but never forwarded that...
Chat attachment uploads authenticate before the body is spooled
POST /sessions/{guid}/attachments bound its parts as a @RequestParam MultipartFile[] method parameter. Spring resolves method parameters before a controller met...
DocsService is no longer published directly at docs-api.kamocrm.com
The docs-api-ingress IngressRoute sent the internet straight to DocsService, around the api gateway (and its identity-header stripping). Nothing used the host: ...
Like what you see shipping?
All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.
