KamoCRM

Live Change Log

Every feature, fix and improvement, posted as it ships. Nothing is held back for a launch.

15,120
Total Changes
5,169
Features
4,935
Fixes
30
Projects
Filter by project
All Projects15,120AIService197APIService161BillingService143ConversionService107DaemonService129DocsService215ESigService88EmailService518InitializerService318KBService105KlusterServices697MCPGatewayService85MediaService546RAGService71SecurityService1,658TranslateService55VOIPService205VectorService11kamo-apps25kamo-asterisk-support24kamo-capcha17kamo-capcha-widget4kamo-internal6,937kamo-login330kamo-marketing625kamo-nowww20kamo-register213kamo-shared-library1,455kamo-signer-monorepo53kamolos108
Filter by type
All TypesBuild11CI523Chore738Docs2,167Feature5,169Fix4,935Other986Performance157Refactor274Revert23Style42Test94Upgrade1
September 28, 2026
FixAPIService

The FreePBX helper's one key rings a phone

kamo-asterisk-support holds a single API key, documented and issued as a VOIP_RECORDING_UPLOADS key, and sends its ring events with it. The ring endpoint accept...

Kamo·14h ago
FixAPIService

Give a public chat's own turns the message rate limit, not the session one

Every public-chat path lives under /sessions/, so the limiter's contains("sessions") test put the conversation itself on the session-creation budget: 3 requests...

Kamo·23h ago
September 24, 2026
FixAPIService

KamoAI internal endpoints never leave the gateway

Carves the seven KamoAI internal subtrees (master spec §7 item 13) out of the wildcard forwards, and with them the server-to-server endpoints that predate the p...

Kamo·4d ago
September 23, 2026
FixAPIService

Give the gateway a memory request and limit

The deployment had no resources: block at all. No request, so the scheduler could not reason about this pod's footprint; no limit, so nothing capped the JVM's -...

Kamo·5d ago
FixAPIService

Forward commission Stripe Connect webhooks, which reached nothing at all

CommissionService registers **************** directly with Stripe (OrgStripeSetupService), but no /api/commissions/** forward existed anywhere in this gateway -...

Kamo·5d ago
FixAPIService

Carve out VOIPService's internal SMS-template API, and never forward a client's own X-Internal-Auth

Two related gaps in the same trust boundary. /api/voip/sms/templates/** was forwarded wholesale by the /api/voip/** wildcard. VOIPService's InternalAuthFilter ...

Kamo·5d ago
FixAPIService

Derive X-Real-IP from the right-most hop, not the client's own

forward() set the outgoing X-Real-IP to X-Forwarded-For.split(",")[0] -- the LEFT-most hop, which is the one part of that header a client controls outright: a r...

Kamo·5d ago
FixAPIService

Bound upstream calls with a connect and a read timeout

Both RestTemplate beans were built from a bare JdkClientHttpRequestFactory with no timeout at all. One upstream that accepts the connection and then never answe...

Kamo·5d ago
FixAPIService

Stop logging session tokens, OTKs and auth headers on every request

forward() printed the entire copied-header map on every single call -- System.out.println("APIService: copied headers: " + outHeaders) -- which serializes X-***...

Kamo·5d ago
September 13, 2026
FixAPIService

Accept OCI image indexes when resolving the built digest [skip ci]

The images are pushed as OCI image indexes, so asking the registry for a single image manifest only answered 404, the digest came back empty and the check faile...

Kamo·2w ago
FixAPIService

Restart when a same-commit rebuild leaves pods on the old digest [skip ci]

The rollout step tried to detect a same-commit rebuild by comparing the Deployment's image reference before and after `set image`. "Apply manifests" has already...

Kamo·2w ago
September 10, 2026
FixAPIService

Never forward client-supplied identity headers upstream

forward(), forwardWebhook() and forwardCallback() copied every inbound header except Host (and, for the sessionless two, the credential headers) onto the upstre...

Kamo·2w ago
September 7, 2026
FixAPIService

Forward carrier SMS webhooks, which reached nothing at all

Traefik sends every path on api.kamocrm.com to this gateway with no path split, and this class forwarded /api/voip/** and nothing else. So /api/bulktext/inbound...

Kamo·3w ago
FixAPIService

Forward carrier SMS webhooks, which reached nothing at all

Traefik sends every path on api.kamocrm.com to this gateway with no path split, and this class forwarded /api/voip/** and nothing else. So /api/bulktext/inbound...

Kamo·3w ago
September 5, 2026
FixAPIService

Prove the deploy by digest, not by tag

The preceding commit stops `set image` being a silent no-op. This asserts the outcome: after the rollout, the tag is resolved to a digest at the registry and th...

Kamo·3w ago
FixAPIService

A rebuild of the same commit deployed nothing and reported success

The image is tagged with the commit SHA, so rebuilding the same commit produces an identical image reference. `kubectl set image` then changes nothing, the Depl...

Kamo·3w ago
FixAPIService

Drop the /api/settings forward, which pointed at nothing

EmailService serves the sync-integration controller at **************** not /api/settings/integrations — so that forward reached a path the service does not map...

Kamo·3w ago
FixAPIService

Route /api/contacts, /api/calendar and /api/settings to EmailService

KamoMobile's contacts and calendar screens 404'd on every request. Neither path was routed at the api host, so nothing reached EmailService and the service logg...

Kamo·3w ago
September 4, 2026
FixAPIService

Give the rollout room for the 15s minReadySeconds now costs

progressDeadlineSeconds was 60. That is the window a rollout has to show progress before Kubernetes gives up and marks it failed, and the previous commit added ...

Kamo·3w ago
FixAPIService

APIService never shut down gracefully at all

Deploys replaced the only pod of each service with nothing to catch the requests in flight. Three settings, applied across the fleet: - preStop sleeps 10s befo...

Kamo·3w ago
August 25, 2026
August 7, 2026
FixAPIService

Encode the decoded token exactly once on the way upstream

21670e5 routed SocialWebhookController through UpstreamUri's FULLY-PRE-ENCODED entry point, but its URL is a hybrid: `token` is an @PathVariable, so Spring hand...

Kamo·1mo ago
FixAPIService

Forward the caller's query bytes on the public-facing proxies

The gateway stopped double-encoding forwarded query strings in 3c24d32, but four other proxies in this service still concatenated already-percent-encoded bytes ...

Kamo·1mo ago
FixAPIService

Forward the caller's query bytes instead of encoding them twice

Every URL this gateway builds is assembled from getRequestURI() and getQueryString() — both already percent-encoded — and was then handed to RestTemplate as a S...

Kamo·1mo ago
August 3, 2026
FixAPIService

Harden the kubectl download against flaky egress [skip ci]

dl.k8s.io over the runner's egress intermittently drops mid-transfer: curl: (56) OpenSSL SSL_read: decryption failed or bad record mac which fails the deploy ...

Kamo·1mo ago
July 16, 2026
FixAPIService

Defer mandatory-origin to Phase 1 — OriginMatcher opt-in (empty allow-list / missing Origin allowed)

Phase-0 widgets still call via their server-side proxy, so origin-locking has no benefit yet and every live public-chat key has an empty allow-list. Strict enfo...

Kamo·2mo ago
July 15, 2026
FixAPIService

Only cache-invalidate genuinely-invalid keys, not origin-denied (prevents valid-key DoS)

On a cold Redis cache, a valid public-chat key with a wrong/absent Origin was cached as INVALID for 60s, denying the correct origin's requests for that window. ...

Kamo·2mo ago
FixAPIService

Bind WS relay handshake to Origin + add cold-cache key validation fallback

Extracts PublicChatController's private validateViaDownstream() into a shared PublicChatKeyResolver bean so PublicChatWebSocketHandler can reuse the same downst...

Kamo·2mo ago
April 27, 2026
FixAPIService

Carve /api/voip/recordings/** out of the wildcard VOIP forwarder

The /api/voip/** catch-all in APIGatewayController was shadowing the dedicated VoipRecordingUploadController POST /api/voip/recordings/upload mapping when Sprin...

Kamo·5mo ago
April 26, 2026
FixAPIService

Raise file upload size limit to 500MB

Spring Boot defaults cap multipart parts at 1MB, causing background image uploads to fail with 500 in request.getParts(). Match SecurityService's existing 500MB...

Kamo·5mo ago
April 25, 2026
FixAPIService

Move CORS to Traefik via kamo-middlewares, remove in-app CorsFilter

The CorsFilter @Bean in the Spring app was silently not applying headers after WebConfig.java was removed. CORS is now handled entirely at the Traefik layer by ...

Kamo·5mo ago
FixAPIService

Remove duplicate CorsFilter and strip upstream CORS headers in gateway

WebConfig.java defined a second CorsFilter bean competing with CorsConfig.java's bean, risking duplicate header writes. Deleted it so only one CorsFilter exists...

Kamo·5mo ago
April 21, 2026
FixAPIService

Set application/json for JSON bodies forwarded to SecurityService

RestTemplate to upstream could leave Content-Type incompatible with Spring @RequestBody, causing 415. After reading the raw body, force APPLICATION_JSON when th...

Kamo·5mo ago
April 19, 2026
April 11, 2026
FixAPIService

Validate Forgejo HMAC-SHA256 signature instead of plain secret header

Forgejo sends webhook secret as X-Gitea-Signature / X-Forgejo-Signature HMAC-SHA256 hash, not as a plain header value. Read body, verify HMAC, then forward to S...

Kamo·5mo ago
April 4, 2026
FixAPIService

Include SUBSCRIPTION_CATALOG in default scopes fallback

When MediaService doesn't return scopes in the validation response, default to including both PUBLIC_CHAT and SUBSCRIPTION_CATALOG scopes. This ensures public c...

Kamo·5mo ago
March 29, 2026
FixAPIService

Use getServerName() instead of getHeader(Host) for original host resolution

ForwardedHeaderFilter consumes X-Forwarded-Host and adapts getServerName() accordingly, while getHeader(Host) returns the raw HTTP Host which may be a K8s inter...

Kamo·6mo ago
FixAPIService

Use HTTP on port 80 for meet service URL to match other services

The HTTPS endpoint on 8443 causes SSL cert mismatch when routing through K8s internal DNS. All other services use HTTP on port 80.

Kamo·6mo ago
March 28, 2026
FixAPIService

Preserve upstream X-Forwarded-Host instead of overwriting with own Host

When an upstream proxy (Next.js) sets X-Forwarded-Host to the browser's original host, APIService now preserves it instead of overwriting with its own Host head...

Kamo·6mo ago
March 23, 2026
FixAPIService

Explicitly forward visitor IP to downstream services

ForwardedHeaderFilter consumes X-Forwarded-For from the incoming request, so when APIService forwards to SecurityService via RestTemplate the header is missing....

Kamo·6mo ago
March 22, 2026
FixAPIService

Move AccessEnforcementFilter to scanned package, revert ComponentScan

The widened @ComponentScan caused a corsFilter bean conflict between CorsConfig and WebConfig. Moved the filter into com.kamo.api.app.config (already scanned by...

Kamo·6mo ago
March 21, 2026
FixAPIService

Add Redis connection config to K8s configmap

APIService pod was failing to start because spring-boot-starter-data-redis auto-configuration couldn't connect to Redis at localhost:6379. Points to redis.kamo....

Kamo·6mo ago

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing