ConversionService is no longer published to the internet
The conversion-api.kamocrm.com IngressRoute sent anyone on the internet to this service, where several endpoints (/image/resize-bg, /favicon/generate, /convert-...
Strip client-supplied identity headers at the media.* edge
media-route (HostRegexp ^media[.].+$) carried only media-websocket-upgrade, so a caller hitting media.<domain> directly could set X-Org-Id, X-Member-Id, X-Publi...
Presence bulk reads and the stale-presence sweep stop using Redis KEYS
getBulkPresence/getBulkLastSeen ran KEYS PRESENCE:*/PRESENCE_LAST_SEEN:* on every call - hit on every presence-socket mount and tab focus - and the 30s sweep ra...
Auth on the endpoints that can take it now, ffmpeg/Batik hardening on the rest
ResourceServerConfig permits every request (this service is reachable anonymously at conversion-api.kamocrm.com), and none of ImageOpsController's or Conversion...
Give the gateway a memory request and limit
The deployment had no resources: block at all. No request, so the scheduler could not reason about this pod's footprint; no limit, so nothing capped the JVM's -...
Forward commission Stripe Connect webhooks, which reached nothing at all
CommissionService registers **************** directly with Stripe (OrgStripeSetupService), but no /api/commissions/** forward existed anywhere in this gateway -...
Carve out VOIPService's internal SMS-template API, and never forward a client's own X-Internal-Auth
Two related gaps in the same trust boundary. /api/voip/sms/templates/** was forwarded wholesale by the /api/voip/** wildcard. VOIPService's InternalAuthFilter ...
Stop logging STOMP frame headers/payloads and /ws request headers
Two leftover debug-logging spots on the WebSocket path: - WebSocketConfig's inbound channel interceptor logged every STOMP frame at INFO, including accessor....
Derive X-Real-IP from the right-most hop, not the client's own
forward() set the outgoing X-Real-IP to X-Forwarded-For.split(",")[0] -- the LEFT-most hop, which is the one part of that header a client controls outright: a r...
Bound upstream calls with a connect and a read timeout
Both RestTemplate beans were built from a bare JdkClientHttpRequestFactory with no timeout at all. One upstream that accepts the connection and then never answe...
Stop logging session tokens, OTKs and auth headers on every request
forward() printed the entire copied-header map on every single call -- System.out.println("APIService: copied headers: " + outHeaders) -- which serializes X-***...
Internal-auth secret comparisons are constant-time and fail closed
TranscriptionController, RecordingIngestController and RecordingProcessController all compared X-Internal-Auth with String.equals (a timing oracle on a shared s...
Imaging proxy forces a download for anything that isn't a safe raster or a stream
GET/HEAD **************** always answered with the client-declared Content-Type from upload, no Content-Disposition, no X-Content-Type-Options and no CSP. ChatA...
The meet-provider OAuth result page can no longer break out of its own script tag
MeetProviderController's GET /oauth/callback is sessionless and reflects the provider's error_description into an inline <script> block. The old jsString() only...
The learner media route's HEAD answers instead of hanging
useAttachmentSource probes with a HEAD after a media element fails, to tell a file that is gone from a session that lapsed. The route awaited response.body.canc...
The internal envelope API fails closed and compares its secret in constant time
**************** used String.equals against X-Internal-Auth (a timing side channel on a shared secret) and, when esig.internal-auth-secret was unset, logged a w...
The staff envelope API now requires a document right, and HR envelopes need an HR one
EsignEnvelopeController's **************** checked org membership only — no document right, no clearance, nothing context-specific. Any authenticated staff memb...
Thread orgId through every template handler, EDIT_DOCUMENTS on writes
ESignTemplateService's signer/design handlers (getSigners, upsertSigners, reorderSigners, deleteSigner, saveDesign, getLatestDesign, listDesignVersions, getDesi...
RegisterExistingDocument checks the dat's org, and a template can be found by imgId within one
Two org-scoping gaps the esig/imaging audit found, both in shared entry points other services build on: - **************** (the conversion service's dedup-skip...
The Hold'em invite is a kind the site knows: label, icon, filter and mute
MediaService has raised HOLDEM_INVITE notifications since Hold'em shipped, but the kind was missing here: the toast's eyebrow printed the raw translation key, t...
Gate adding people and moving a position as the server does, and list every storage area
- The Add and Bulk Add buttons on /account, and the four create pages, need MANAGE_MEMBERS (MemberAdministrationGate), which SecurityService now enforces. Som...
Five reasons the golden image had never actually been built
The build had never been run. Running it found one bug per attempt, and the first three would each have produced a plausible-looking image with something missin...
Count an org's unconfirmed talent-alert rows for the anonymous form's cap
DocsService's public talent-alert subscribe endpoint sends a confirmation email on every accepted call, with no limit on how many not-yet-confirmed rows one org...
UpdateDocType now requires the doc type to belong to the document's own org
ImageService.updateDocType loaded the target ImgDocType by UUID alone; requireEditableAndOwned proves the caller may edit the Img, but says nothing about whose ...
Org-scoped counterparts for the thumbnail-backfill candidate queries
DocsService's /backfill-thumbnails admin endpoint selected candidates from **************** (platform-wide, no organization predicate) or, as a last resort, a r...
Clearing the image version has to send "", not null
**************** merges rather than replaces, and for the image version a null means "leave whatever is there alone" — only a blank string clears it: if (i...
Right checks, SSRF/credential guards and cross-org fixes across VOIP
Findings 2-6 from the phone-system audit, fixed together because several share files. 2. HIGH — VoipInstanceController had no right check on any mutating endpo...
Adding people and member security need their rights
POST /members/create, /create-team-member and /bulk-create, and GET /members/lookup-user, now require MANAGE_MEMBERS or an open god window. They checked only fo...
The platform tab, and three links that showed their own keys
Two bugs, both reported from the running site. THE SETTINGS LINKS SHOWED KEY PATHS The three Hosted Computer sub-links carried key: 'computers' | 'capacity' | ...
Require MANAGE_DOCS_SETTINGS on every doc-settings mutation, not just some
The settings page always sent a member without MANAGE_DOCS_SETTINGS away, but ten mutation endpoints in ImagingSettingsController never asked themselves: canMan...
Scope thumbnail backfill to the caller's org; gate history reads by clearance
Two independent gaps in ImagingController: - /backfill-thumbnails selected candidates platform-wide (no organization predicate at all; the last-resort tier w...
Throttle the anonymous careers talent-alert form
CareersPublicController's POST /{orgRef}/alerts is the one anonymous, unauthenticated endpoint in this service that sends an email on every accepted call, with ...
UpdateDocType now requires the doc type to belong to the document's own org
ImageService.updateDocType loaded the target ImgDocType by UUID alone; requireEditableAndOwned proves the caller may edit the Img, but says nothing about whose ...
Org-scoped counterparts for the thumbnail-backfill candidate queries
DocsService's /backfill-thumbnails admin endpoint selected candidates from **************** (platform-wide, no organization predicate) or, as a last resort, a r...
Count an org's unconfirmed talent-alert rows for the anonymous form's cap
DocsService's public talent-alert subscribe endpoint sends a confirmation email on every accepted call, with no limit on how many not-yet-confirmed rows one org...
An IMAP/SMTP connection test must not be usable as a network probe
POST /api/email/member-imap/test and /{id}/imap/test connected to whatever host and port the caller supplied and returned the raw exception message. Any authent...
Alias, domain and personal-mailbox admin actions need a management right
create/delete on an email alias, **************** on the org's sending domains, and **************** on a personal (self-hosted) mailbox all needed only a sessi...
A member's mailboxes and aliases are only readable inside their own organization
GET **************** took no HttpServletRequest at all — no session, no org check anywhere on the path — and GET **************** checked that the CALLER had a ...
A calendar export or import must be one the caller can actually open
GET /export/calendar/{id} and POST /import/{calendarId} took the calendar's UUID alone — no HttpServletRequest, so no session, no org or member check at all. An...
Gate the API on the app, not only the screen
The settings page and the nav option both check organization.isHostedComputers, and until now that was the whole gate. AppAvailabilityInterceptor never mapped /...
A Hosted Computer is never provisioned automatically
Hosted Computers was reachable by both automatic provisioning paths, and either one would have put it in front of every organization on the platform at once. F...
The three templates that never got committed
service-template.yaml, cloud-init.userdata.yaml and cloud-init.networkdata.yaml. They were written into a second worktree and committed from neither — the earli...
SearchService marks its injection constructor, so the service starts
9809d4b gave SearchService a second constructor (a clock, for tests) and marked neither, so Spring chose neither, looked for a no-argument constructor, and the ...
Every folder of a switched-to mailbox works, and search is rebuilt
Switching mailboxes. The folder sidebar always loaded the member's OWN folder tree, whatever mailbox was open - so a second mailbox showed the primary's folders...
Search that honours its query, and every mail action on the mailbox that is open
Two problems on /messages, fixed in the service. Search did not work. The index path threw a ClassCastException on every hit (Instant -> Timestamp, visible in ...
Shared-mailbox **************** need a management right
**************** on /api/email/shared-mailboxes needed only a session — any authenticated member could create a shared mailbox, delete one, or grant themselves ...
Apply the per-party/issued/trashed checks everywhere byte-adjacent paths need them
**************** applied the issued-document check but not the per-party (ACCOUNT_MEMBER_VAULT/LOAN) or trashed-row checks that /download, /stream and the sibli...
Verify RingCentral webhooks before trusting them
RingCentral's inbound call/SMS webhooks were processed with zero verification: WebhookController routed telephony/message-store events straight into ***********...
An OAuth state token is a server-side record, not a blob the browser hands back
/api/email/oauth/callback and **************** are public and sessionless (the provider redirects the browser here with no Kamo session), so `state` was the onl...
A document share now actually reaches its recipient, and edit is gated
**************** matched an ImgShare by ImgShare.member — the SHARER, who created the row so they can list what THEY shared (getSharesByImage) — instead of ImgS...
Like what you see shipping?
All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.
