Understand Bilty signature PNG validation
Understand the server-side checks for PNG structure, CRCs, dimensions, decompression bounds, visible ink, trailing data and file size. The guide follows the Help Centre standard: exact route, prerequisites, ordered steps, verification and operational boundaries.
What you’ll accomplish
Understand the server-side checks for PNG structure, CRCs, dimensions, decompression bounds, visible ink, trailing data and file size. Bilty Management keeps drafts, issued records, public capability links, finance, integration events and audit evidence as connected but separately verifiable records.
How the workflow fits together
Verify issued Bilties publicly, configure permitted fields and collect protected receiver POD signatures. Use the module's current status, permission checks, warnings and linked records to decide the next supported action. Where a downstream invoice, WhatsApp queue item, webhook, PDF, POD record or audit event applies, verify it separately.
Follow these steps
- Go to Secure receiver e-sign receipt and open the relevant current record or configuration view.
- Review the displayed state and compare it with the explanation in this guide.
- Compare the live values with the workflow described in this guide: Understand the server-side checks for PNG structure, CRCs, dimensions, decompression bounds, visible ink, trailing data and file size.
- Follow any linked record, status, public evidence, invoice, queue or audit entry rather than inferring that a downstream action happened.
- Use the related guides below for the operational action that changes the record.
Fields and decisions to review
Record, audit and evidence checks
Reopen the relevant Bilty record or register and confirm its identifier, current status, related parties, timestamps and connected evidence. Check the audit/compliance, payment, public-link, report, API, webhook or WhatsApp evidence that applies to this workflow rather than relying only on a success alert.
How to confirm it worked
Return to Secure receiver e-sign receipt or the resulting register and verify that the stored state matches the intended action. For any downstream automation, confirm the downstream record or queue/log entry as a separate completion check.
Technical basis for this guidance
This guide was checked against config/routes.php; controllers/Bilty_public.php; models/Bilty_management_model.php; views/public/verify.php; views/public/sign.php; assets/js/public_esign.js. It documents only behaviour exposed or enforced by the supplied module; internal secrets, raw signature payloads and unsupported future workflow assumptions are intentionally excluded.
Controls, checks and common mistakes
- Public verification never exposes price/payment data or private contact numbers.
- Receiver e-sign depends on public verification and fails closed when the dependency is disabled.
- Do not treat possession of a public capability URL as staff authentication.
