Force KamoMobile Logout on a member's account activity

Featurekamo-internal
Shipped
September 4, 2026 at 3:08 AM UTC
Author
Kamo
Commit
73b5704

Force Logout deletes sessions, which ends a browser. It does not end a phone: KamoMobile holds a durable device token and mints a fresh session from it immediately, so pressing Force Logout on a lost handset looks like it worked and changes nothing. The new button revokes the devices themselves. It matters more now that KamoMobile can open a fully interactive terminal on the member's dev machine: whoever is holding an unlocked handset has a shell on a box with a cluster-admin kubeconfig until this runs. Also allow-lists the forwarded action. It lands in the upstream PATH, so an unchecked value carrying '..' segments could aim an authenticated POST at a different SecurityService endpoint. Those all authorize themselves, so this is a second line rather than the only one — but the first line should not be 'the HTTP client happens to normalize that'.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing