KamoCRM

Live Change Log

Every feature, fix and improvement, posted as it ships. Nothing is held back for a launch.

15,120
Total Changes
5,169
Features
4,935
Fixes
30
Projects
Filter by project
All Projects15,120AIService197APIService161BillingService143ConversionService107DaemonService129DocsService215ESigService88EmailService518InitializerService318KBService105KlusterServices697MCPGatewayService85MediaService546RAGService71SecurityService1,658TranslateService55VOIPService205VectorService11kamo-apps25kamo-asterisk-support24kamo-capcha17kamo-capcha-widget4kamo-internal6,937kamo-login330kamo-marketing625kamo-nowww20kamo-register213kamo-shared-library1,455kamo-signer-monorepo53kamolos108
Filter by type
All TypesBuild11CI523Chore738Docs2,167Feature5,169Fix4,935Other986Performance157Refactor274Revert23Style42Test94Upgrade1
September 29, 2026
FixSecurityService

AI-டிஸ்பேச் தணிக்கை பாதை அரட்டை செய்வது போலவே நபர்களின் பெயர்களையும் குறிப்பிடுகிறது

* * * * * * * * * * * * * * கையால் நகலெடுக்கப்பட்ட உறுப்பினர் DisplayNames ' முன்னெச்சரிக்கை முன்னுரிமை (பயனர் பெயர்Alias உண்மையான பெயரை விட நிபந்தனையற்ற வெற்றி...

Kamo·2h ago
September 28, 2026
FixSecurityService

An address on either platform apex signs in to the account holding its twin

The owner signed in on login.kamouniverse.com with the brand's new address and was told "User does not exist". The account's address is Sage@KamoCRM.com. Since ...

Kamo·8h ago
FixSecurityService

A like is stamped, so it saves

media_obj_reports.date_created is NOT NULL, and the like was built without it: @ColumnDefault only shapes the DDL, so Hibernate wrote NULL and every like failed...

Kamo·9h ago
FixSecurityService

Edit, like and delete one post or note by its own id, never the whole stream

A feed, the organization's (the Clubhouse) or a lead's notes, is ONE POST session and every post or note is a message in it, so every item the feed lists carrie...

Kamo·10h ago
FixSecurityService

SPF advice recognises kamouniverse.com; the brand's aliases are reserved on both apexes

SPF: kamouniverse.com publishes the same record as spf.kamocrm.com (v=spf1 ip4:47.181.8.84 mx -all), so a customer who wrote include:kamouniverse.com has alread...

Kamo·10h ago
FixSecurityService

Platform fallbacks name the primary apex, not a kamocrm.com literal

Four places kept their own "kamocrm.com" literal as the platform host they fall back to, so they could never follow the brand to kamouniverse.com. Each now read...

Kamo·10h ago
FixSecurityService

One organization can no longer take another's <alias>.kamocrm.com routing

Any member of an organization with no root could add the root victim.kamocrm.com (POST /api/security/domains checked no right). Listing the domains then self-he...

Kamo·11h ago
FixSecurityService

A lead's notes stream, addressed by its guid, keeps the lead's own read rule

Every note on a lead now sends the lead stream's guid on /topic/media/feed/<orgId> (SP99-T3), which any member of the organization may subscribe to. The guid-ad...

Kamo·11h ago
FixSecurityService

A new commit log is translated at once, not behind the sweep's backlog

The first translation of a commit log and the sweep's retries shared one three-thread executor, first come first served. With the SP99 T6 repair's 326 commit lo...

Kamo·13h ago
FixSecurityService

The translation recount is the first statement of its own transaction

A locale save was an upsert and then a recount that reads the commit log's rows, in one transaction. Yugabyte restarts a read transparently only when it is the ...

Kamo·13h ago
FixSecurityService

One pod at a time translates a commit log, and a finished one is not redone

Both SecurityService pods run the translation sweep: its lock lasts only as long as the dispatch. Each took up the same 50 commit logs, and a pod's in-flight se...

Kamo·14h ago
FixSecurityService

A re-translation no longer deletes the translation it replaces

Since 1f715e4 (2026-09-23) saveLocaleTranslation loaded the locale's row to decide whether the count moved, bulk-deleted it and saved a new one. The load left t...

Kamo·16h ago
FixSecurityService

Close the AI identity edge cases the SP02 review left open

- A never-hired AI relabelled a person no longer keeps ai_state and the pause columns (master 6.1: NULL for a person). They are written only by SQL, so the ...

Kamo·18h ago
FixSecurityService

A lead you may not open takes no status change and no note

PUT /api/security/leads/{id} and POST /api/security/media/posts checked only the lead's organization, so a member without VIEW_UNASSIGNED_LEADS could change the...

Kamo·18h ago
FixSecurityService

CalDAV and CardDAV sign in with a username and password, through every sign-in gate

EmailService's DavAuthFilter posted Basic credentials to **************** a route that never existed (405), so since 2026-03-19 no phone (iOS, DAVx5) could add ...

Kamo·19h ago
FixSecurityService

Clear the session cookie on the bare apex, not ".apex"

Logout built the cookie domain as ".kamocrm.com". Tomcat's RFC 6265 cookie processor refuses a leading dot and throws, so logout answered 500 "Logout failed" af...

Kamo·19h ago
FixSecurityService

A platform apex can't be removed from the DNS page

The platform organization gained kamouniverse.com as a second root domain, and the DNS page then offered "Remove" on kamocrm.com. Deleting it took kamocrm.com a...

Kamo·19h ago
FixSecurityService

Two more root-domain picks follow OrgDomains.primaryDomain

BranchTypeController's parentRootDomain (the create-branch wizard's web-alias zone) and PortalAccountController's api.<root> (borrower-portal sign-in) each took...

Kamo·22h ago
September 27, 2026
FixSecurityService

Watch and Take over open their connection in the gateway's client

Guacamole 1.5.5's client reads the #/client/<id> fragment with atob (one character per byte) and btoa's every connection name it lists, so a name outside Latin-...

Kamo·1d ago
September 25, 2026
FixSecurityService

A loan Kamo creates now links, and a refused one says why on the lead

Ian's Create Loan reached Arive, was refused inside the Zap, and Kamo never knew: Zapier had already answered 200, and Arive fires no new_loan for a loan made t...

Kamo·3d ago
FixSecurityService

A hire-step owner answering 401 has not shipped yet, so the step waits

VOIPService and ComputeService answer any path they do not serve from their session layer with 401, so Ava's EXTENSION and WORKSTATION steps went FAILED before ...

Kamo·3d ago
FixSecurityService

An AI member never founds an organization

The second door to IMPORTANT-1 of the SP02 final review. POST /api/security/organizations needs no right for a standalone organization: any signed-in user may c...

Kamo·3d ago
FixSecurityService

Security-model writes require CONFIGURE_SYSTEM

Closes the SP02 final review's IMPORTANT-2. POST /api/security/models, PUT and DELETE /api/security/models/{id} and PUT /api/security/master-model only resolved...

Kamo·3d ago
FixSecurityService

An AI member is never an owner or a platform operator

Closes the door around the AI never-grantable floor that the SP02 final review found (IMPORTANT-1). Platform rights and the owner flag are not RoleRightTypes, s...

Kamo·3d ago
FixSecurityService

A verification resend that names its account goes to the account's own org

An organization with no domain has no register host of its own, so its members land on register.<platform apex>, whose host names the platform. The resend endpo...

Kamo·3d ago
FixSecurityService

A hot reassign's first note creates the lead's stream linked to the lead

The stream is created for the lead, as the lead view's feed creates it, so its MEDIA_SESSION_POST row carries LEAD_ID and POST_CREATED goes to media.feed.lead.<...

Kamo·4d ago
September 24, 2026
FixSecurityService

Point loan officers at the card they will actually find — Lender credentials

Both the MeridianLink and the Arive 'officer not linked' refusals named cards that no longer exist under those titles.

Kamo·4d ago
September 23, 2026
FixSecurityService

The forgot-password hint is the account's address, whatever it is

d7ff5ed called the address on the user account "personal" everywhere: in the 409's message, the response field and the class. It is not always personal. An admi...

Kamo·5d ago
FixSecurityService

Gift cards take the Discounts tab's pricing rights

Listing gift cards, issuing one and editing one (including its balance, which the shared library sets again as of the companion kamo-shared-library commit) chec...

Kamo·5d ago
FixSecurityService

A member's official title and status need member security too, on their own record

Department and job title already needed MANAGE_MEMBER_SECURITY (or an open god window) on /member-security, your own record included. The rest of the Position c...

Kamo·5d ago
FixSecurityService

CommerceMarketController's retail sub-resources are org-scoped

CommerceMarketController's get-one/update/delete handlers under /retail/... called RetailService methods that took no orgId (bare findById/deleteById) - a same-...

Kamo·5d ago
FixSecurityService

Drop 4 newly-guarded handlers from the unguarded-endpoints ratchet

**************** caught the previous commit: **************** and **************** now resolve a session (getCachedOrganizationId, in each handler's own body), ...

Kamo·5d ago
FixSecurityService

Scope roles, member access and profile writes to the caller's org

Five gaps let a signed-in member reach outside their own organization, or reach a colleague's account, with no right check: - **************** resolved no sess...

Kamo·5d ago
FixSecurityService

Forward the actor when relaying a commission line

addLine/updateLine relayed memberId (normalized to Long in 789c544) but never who was making the call — unlike openDraft, send, voidLine and every Stripe-config...

Kamo·5d ago
FixSecurityService

Forward subjectMemberId and role so TimecardService can verify punch ownership

**************** resolved the caller's role against a CLIENT-SUPPLIED subjectMemberId (resolveRole -> EMPLOYEE whenever actor==subject) but never forwarded that...

Kamo·5d ago
FixSecurityService

Adding people and member security need their rights

POST /members/create, /create-team-member and /bulk-create, and GET /members/lookup-user, now require MANAGE_MEMBERS or an open god window. They checked only fo...

Kamo·5d ago
FixSecurityService

Gate the API on the app, not only the screen

The settings page and the nav option both check organization.isHostedComputers, and until now that was the whole gate. AppAvailabilityInterceptor never mapped /...

Kamo·5d ago
FixSecurityService

Intake endpoints show exact received/imported counts from the intake ledger

The Lead Intake settings list showed total_received / total_processed / last_received_at straight off the endpoint row, where they were bumped once per payload ...

Kamo·6d ago
September 19, 2026
FixSecurityService

Normalize memberId when relaying line add/update requests

The browser keeps member ids as strings to avoid IEEE-754 rounding on CockroachDB unique_rowids. Normalize to Long before relaying so the credit lands on the in...

Kamo·1w ago
September 18, 2026
FixSecurityService

The account view names its primary member

GET /customers/{uid} sent the primary member only as primaryMemberId, while the account view reads a primaryMember object — so its Primary member row read "---"...

Kamo·1w ago
FixSecurityService

An account note names the member who wrote it, not "System"

GET /customers/{uid}/notes sent each note's authorMemberId but no authorName, and the account view shows a note with no name as written by the system — so every...

Kamo·1w ago
September 17, 2026
FixSecurityService

Short one-time codes can no longer be guessed without limit

Every short code the platform mails or texts was checked with no count: - POST /api/recover/email/verify-code took the 8-hex-character reset code ALONE and mat...

Kamo·1w ago
FixSecurityService

Securityservice never stores a password as typed

Two writers put plaintext into USERS.PASSWORD. Both called User.encodePassword(), which needs a static encoder that only initializerservice ever sets **********...

Kamo·1w ago
FixSecurityService

Retail store connections are reachable only by their own org's commerce settings managers

The retail provider-config handlers on CommerceMarketController resolved the session's org and then used whatever market and config uid the path named. Update, ...

Kamo·1w ago
FixSecurityService

The System User acts only inside the organization it was entered into

There is one System User for the whole platform. Platform operators, and support staff holding a grant scoped to a single ticket's organization, enter a tenant ...

Kamo·1w ago
FixSecurityService

Only an org's owner, its CONFIGURE_SYSTEM members or active god mode can change its settings

PUT /api/security/org/{id} took no request at all. ResourceServerConfig permits every request and APIService relays /api/security/**, so one anonymous request c...

Kamo·1w ago
FixSecurityService

An OAuth app save keeps its client secret unless a new one is typed; owners' credentials stay out of org JSON

PUT /api/oauth-config/{id} stored whatever arrived under clientSecret. Responses mask the secret, and the edit form sends a blank back while promising "Leave bl...

Kamo·1w ago

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing