Public scanning and signing

Understand QR signing transaction and concurrency

This guide explains that how the model prevents two successful signatures on one pending record. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.

Audience: Administrators and developersPermission: Staff loginModule v2.1.1
Jump to steps
Where to goPublic QR page → Submit signature
Before you start
  • Use an authorised account and confirm the source CRM record or setting is correct.
  • Follow the exact route shown above; do not force database values to imitate a completed action.

What you’ll accomplish

Know how the model prevents two successful signatures on one pending record. These instructions follow the supplied module’s live hooks, controller, model, view and validation flow.

Follow these steps

  1. Use the public form once.
  2. If two submissions race, allow the server to resolve the current record state.
  3. Check the final signed record.

Fields and options to review

Action scopeKnow how the model prevents two successful signatures on one pending record.
Module version2.1.0
NavigationPublic QR page → Submit signature
EvidenceVerify the stored record, status, output, email, event or log produced by the code path.

Rules the system enforces

  • The model locks the database row FOR UPDATE and updates only a pending record.
  • A second or concurrent submission receives the current already-signed outcome rather than replacing evidence.

How to confirm it worked

  • The requested record, output or setting is created or updated through the supported module flow.
  • Any related status, count, email, audit/event, PDF/file or queue evidence agrees with the source action.
  • An error message is investigated rather than bypassed.

Security, privacy and operational checks

  • Apply least privilege and verify the correct customer, lead, sales document or recipient before processing.
  • Protect public tokens, recipient data, IP/browser evidence, templates and exported files according to organisational policy.
  • Test configuration changes with controlled records before production-wide use.
  • Retain or delete evidence only under an authorised retention process.