Validate provider URLs and network safety
Prevent integrations from calling private or unsafe destinations.
Exact navigationAdmin Area → Courier & Logistics → Settings → Providers
What this guide covers
Prevent integrations from calling private or unsafe destinations. The instructions below follow the supplied module’s controller, form and model rules, including server-side validation and downstream effects.
Exact step-by-step process
- Enter a complete HTTPS base URL.
- Save/test.
- Resolve validation errors before activation.
Fields, choices and supported possibilities
This action uses the values already stored on the selected source record. Review that record before continuing.
Code-backed validations and workflow rules
- Only public HTTPS URLs are accepted.
- Private/local IP destinations are rejected.
- The HTTP client applies a maximum response size of 5 MB.
- TLS verification remains part of the client request.
Expected result and verification
- The source record, status/history and any downstream notification, provider, POD or finance record should agree after the action.
Security, audit and operational checks
- Use the exact record and least-privilege role before changing any state.
- Verify the saved record after every action; a browser message alone is not evidence that every downstream step completed.
- Use protected document and image routes rather than exposing server filesystem paths.
- Keep customer, driver, provider, financial and credential data within the authorised workflow.
- For provider, finance, employment, transport and compliance decisions, follow the organisation’s authorised professional process.
Do not bypass the code flowDo not force database values, invent a status, mark a job completed without signed POD evidence, or expose encrypted credentials to make a screen appear successful.
