Understand Courier public routes
Identify token and webhook endpoints without exposing internal files.
Exact navigationApplication routes → Courier public/API controllers
What this guide covers
Identify token and webhook endpoints without exposing internal files. The instructions below follow the supplied module’s controller, form and model rules, including server-side validation and downstream effects.
Exact step-by-step process
- Open Application routes → Courier public/API controllers.
- Review the source record and choose the supported action.
- Save or submit once, then reopen the record and verify the result.
Fields, choices and supported possibilities
/clm/pod/{token}Public POD page.
/clm/signature/{token}Controlled signature image.
/clm/snapshot/{token}Controlled snapshot image.
/clm/webhook/{provider_slug}Provider webhook receiver.
Code-backed validations and workflow rules
- POD/image access uses the retained token.
- Webhook access uses provider slug plus configured authentication/signature validation.
Expected result and verification
- The source record, status/history and any downstream notification, provider, POD or finance record should agree after the action.
Security, audit and operational checks
- Use the exact record and least-privilege role before changing any state.
- Verify the saved record after every action; a browser message alone is not evidence that every downstream step completed.
- Use protected document and image routes rather than exposing server filesystem paths.
- Keep customer, driver, provider, financial and credential data within the authorised workflow.
- For provider, finance, employment, transport and compliance decisions, follow the organisation’s authorised professional process.
Do not bypass the code flowDo not force database values, invent a status, mark a job completed without signed POD evidence, or expose encrypted credentials to make a screen appear successful.
