E-signature and public verification

Understand Letter Manager signature validation limitations

Do not claim controls that the supplied acceptance endpoint does not enforce server-side.

Audience: Administrators, legal/compliance and developersPermission: Authenticated staff accountModule v1.0.0
Exact navigationPublic signature flow review
Before you begin
  • Use an authorised account and confirm the customer, external recipient, template, letter or configuration is the intended one.
  • Follow the exact route shown above and verify the stored record, generated file and delivery evidence instead of relying on an alert alone.

What this guide covers

Do not claim controls that the supplied acceptance endpoint does not enforce server-side. These instructions follow the inspected module’s live hook, route, controller, model, installer, PDF helper and view flow.

Exact step-by-step process

  1. Use the signature page as the supported recipient flow.
  2. Review required signer fields and image evidence after submission.
  3. Apply additional identity verification outside this module when legal assurance requires it.
  4. Test any future hardening before describing it in policy.

Fields, choices and supported possibilities

Action scopeDo not claim controls that the supplied acceptance endpoint does not enforce server-side.
Module version1.0.0
Exact routePublic signature flow review
EvidenceVerify the history row, PDF, email metadata, open evidence, signature, public page, client view or postal fields produced by this flow.

Code-backed validations and workflow rules

  • The page prevents empty-canvas submission in JavaScript, but the controller does not independently validate that decoded image data is a valid PNG.
  • The accept action does not explicitly check require_signature.
  • The action does not implement a one-time server-side lock before updating the signature fields.

Expected result and verification

  • The requested letter, template, setting, file or tracking detail is created or updated through the supported route.
  • The history row, generated PDF, email/send metadata, public verification, signature evidence, client view or postal display agrees with the action.
  • Any warning, missing file or failed send is investigated rather than bypassed.

Security, privacy and operational checks

  • Apply least privilege and verify recipient identity before sending or exposing public links.
  • Protect PDFs, enclosures, signatures, verification URLs, email-open metadata, IP addresses and customer data under organisational policy.
  • Test configuration and deployment changes with controlled records before production-wide use.
  • Interpret email opens and e-signatures according to their documented technical limitations.
Important code-backed limitationThe supplied e-signature is an acknowledgement workflow, not a qualified electronic-signature or identity-verification service.