Handle invalid verification or signature links
Respond to a 404 without disclosing alternative records or guessing tokens.
Exact navigationPublic verify/sign URL → 404
Before you begin
- Use an authorised account and confirm the customer, external recipient, template, letter or configuration is the intended one.
- Follow the exact route shown above and verify the stored record, generated file and delivery evidence instead of relying on an alert alone.
What this guide covers
Respond to a 404 without disclosing alternative records or guessing tokens. These instructions follow the inspected module’s live hook, route, controller, model, installer, PDF helper and view flow.
Exact step-by-step process
- Check the complete URL was copied without punctuation or line wrapping.
- Ask the issuing organisation to resend the authorised link.
- Staff should locate the record by reference and use Verify or Resend Email.
- Do not enumerate codes or hashes.
Fields, choices and supported possibilities
Action scopeRespond to a 404 without disclosing alternative records or guessing tokens.
Module version1.0.0
Exact routePublic verify/sign URL → 404
EvidenceVerify the history row, PDF, email metadata, open evidence, signature, public page, client view or postal fields produced by this flow.
Code-backed validations and workflow rules
- Unknown unique_code and hash values produce 404.
- The module provides no public lookup form by verification code.
Expected result and verification
- The requested letter, template, setting, file or tracking detail is created or updated through the supported route.
- The history row, generated PDF, email/send metadata, public verification, signature evidence, client view or postal display agrees with the action.
- Any warning, missing file or failed send is investigated rather than bypassed.
Security, privacy and operational checks
- Apply least privilege and verify recipient identity before sending or exposing public links.
- Protect PDFs, enclosures, signatures, verification URLs, email-open metadata, IP addresses and customer data under organisational policy.
- Test configuration and deployment changes with controlled records before production-wide use.
- Interpret email opens and e-signatures according to their documented technical limitations.
