Settings, cron automation and technical code flow

Understand provider-client request flow

Trace endpoint construction, auth, TLS validation and response controls. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.

Audience: Courier operations staffPermission: Courier: AdministratorModule v2.0.0
Jump to steps
Where to goTechnical reference → libraries/Clm_provider_client.php

What you’ll accomplish

Trace endpoint construction, auth, TLS validation and response controls. The instructions below follow the supplied module’s controller, form and model rules, including server-side validation and downstream effects.

Follow these steps

  1. Select provider and action.
  2. Build URL from base/endpoint.
  3. Create auth headers or obtain OAuth token.
  4. Validate public HTTPS destination.
  5. Perform request with payload/size controls.
  6. Return structured success/error to the model.

Fields and options to review

This action uses the values already stored on the selected source record. Review that record before continuing.

Rules the system enforces

  • Supported actions include live jobs, invoices, detail, test, push status, submit POD and upload document.

How to confirm it worked

  • The source record, status/history and any downstream notification, provider, POD or finance record should agree after the action.

Security, audit and operational checks

  • Use the exact record and least-privilege role before changing any state.
  • Verify the saved record after every action; a browser message alone is not evidence that every downstream step completed.
  • Use protected document and image routes rather than exposing server filesystem paths.
  • Keep customer, driver, provider, financial and credential data within the authorised workflow.
  • For provider, finance, employment, transport and compliance decisions, follow the organisation’s authorised professional process.
Do not bypass the code flowDo not force database values, invent a status, mark a job completed without signed POD evidence, or expose encrypted credentials to make a screen appear successful.