Resolve session from X-***-Token header in CallerSessionResolver

FixSecurityService
Shipped
July 7, 2026 at 11:48 PM UTC
Author
Kamo
Commit
0e62afe

The kamo-internal -> APIService BFF path forwards the session as the X-***-Token header, but the resolver only read the X-OTK attribute or the *** cookie — so BaseLosController endpoints (incl. the new KamoDesktop SSO) got no session and 401'd. Add the header as a source (OTK attr -> X-***-Token header -> *** cookie).

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing