Public scanning and signing

Understand QR public security headers

This guide explains that the browser protections applied to the public signing page. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.

Audience: Administrators and security reviewersPermission: Staff loginModule v2.1.1
Jump to steps
Where to goPublic QR page → Response headers
Before you start
  • Use an authorised account and confirm the source CRM record or setting is correct.
  • Follow the exact route shown above; do not force database values to imitate a completed action.

What you’ll accomplish

Know the browser protections applied to the public signing page. These instructions follow the supplied module’s live hooks, controller, model, view and validation flow.

Follow these steps

  1. Go to a valid public page in an authorised test.
  2. Inspect response headers.
  3. Verify noindex/nofollow/noarchive, nosniff, no-referrer, restricted permissions, CSP, frame blocking and no-store caching are present.

Fields and options to review

Action scopeKnow the browser protections applied to the public signing page.
Module version2.1.0
NavigationPublic QR page → Response headers
EvidenceVerify the stored record, status, output, email, event or log produced by the code path.

Rules the system enforces

  • The CSP permits self resources and data images, restricts form action/base URI/frame ancestors and allows geolocation only from self.

How to confirm it worked

  • The requested record, output or setting is created or updated through the supported module flow.
  • Any related status, count, email, audit/event, PDF/file or queue evidence agrees with the source action.
  • An error message is investigated rather than bypassed.

Security, privacy and operational checks

  • Apply least privilege and verify the correct customer, lead, sales document or recipient before processing.
  • Protect public tokens, recipient data, IP/browser evidence, templates and exported files according to organisational policy.
  • Test configuration changes with controlled records before production-wide use.
  • Retain or delete evidence only under an authorised retention process.