Public scanning and signing

Understand server-side QR signature validation

Meet the PNG, byte-size, image-dimension and non-blank checks performed after submission. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.

Audience: Recipients and support staffPermission: Staff loginModule v2.1.1
Jump to steps
Where to goPublic QR page → Submit signature
Before you start
  • Use an authorised account and confirm the source CRM record or setting is correct.
  • Follow the exact route shown above; do not force database values to imitate a completed action.

What you’ll accomplish

Meet the PNG, byte-size, image-dimension and non-blank checks performed after submission. These instructions follow the supplied module’s live hooks, controller, model, view and validation flow.

Follow these steps

  1. Draw the signature in the supplied canvas.
  2. Submit through the form rather than uploading an arbitrary file.
  3. If rejected, clear and draw a fuller signature.

Fields and options to review

Action scopeMeet the PNG, byte-size, image-dimension and non-blank checks performed after submission.
Module version2.1.0
NavigationPublic QR page → Submit signature
EvidenceVerify the stored record, status, output, email, event or log produced by the code path.

Rules the system enforces

  • The value must be a data:image/png;base64 URL.
  • Decoded PNG length must be between 150 and 750,000 bytes.
  • The image must be a valid PNG with acceptable dimensions.
  • Pixel analysis rejects a dot or effectively blank image.

How to confirm it worked

  • The requested record, output or setting is created or updated through the supported module flow.
  • Any related status, count, email, audit/event, PDF/file or queue evidence agrees with the source action.
  • An error message is investigated rather than bypassed.

Security, privacy and operational checks

  • Apply least privilege and verify the correct customer, lead, sales document or recipient before processing.
  • Protect public tokens, recipient data, IP/browser evidence, templates and exported files according to organisational policy.
  • Test configuration changes with controlled records before production-wide use.
  • Retain or delete evidence only under an authorised retention process.