Accepts allowDocumentRejection in the organisation and team settings
update routes, adds it to the default organisation (true) and team
(inherit) settings, and copies the merged value into the document meta
when a document or template is created via extractDerivedDocumentMeta.
Documents created from a template take the template's value, with an
optional override on envelope.use.
Exposes the field in the recipient signing response and refuses
rejectDocumentWithToken requests for documents that disallow rejection,
since the endpoint can be called directly without the UI.
Extends the document preferences and envelope settings e2e tests to
cover inheritance into the team settings and new documents, and
persistence of the per-document value from the editor.
Adds an allowDocumentRejection column to organisation settings (default
true), team settings (nullable, inherits from the organisation) and
document meta (default true), with the migration.
Adds the "Allow Document Rejection" field to the organisation and team
document preferences form, wires it through the settings pages, and lists
it in the reset-to-defaults dialog and the admin settings section. Adds a
per-document Yes/No field to the envelope editor settings dialog.
Exposes the field on the document meta create/update schemas and the
document, envelope, template and editor envelope response schemas, and
hides the reject dialog on the V1 signing page when the document
disallows rejection.
Selecting password auth failed with a generic "Unauthorized" for users
who signed up via OAuth or passkey, with no way to set one.
Detect the missing password and email the existing reset link from the
signing dialog and security settings. Require a 2FA code and rate limit
update-password.
`/api/health` and `/api/certificate-status` reported the cert as
available when `NEXT_PRIVATE_SIGNING_TRANSPORT` was unset, even though
sealing defaults to the local P12 and fails if it is missing,
unreadable, or expired.
Disable autocapture and person profiles for anonymous users, and
redact signing tokens from captured URLs.
Manually wire exception capture into the signing, editor and embed
flows with recipient/envelope context for debugging recipient-reported
issues.
Track activation events (webhooks, api tokens, direct links, embed
sessions) server-side with org attribution, and drop client events
already tracked in-app.
Use our fork of `skia-canvas` for rendering which handles
encoding characters correctly with the caveat font and other
similar fonts that can group glyphs like ligatures.
This resolves issues with pdf text extraction where characters
were unable to be extracted due to lacking any data within the cmaps.
Previously attempting to complete a document which is already completed
you'd get a generic error toast. Now when completing a document that you
have already completed you are redirected to the completed page.
Handles cases where two mutations managed to fire racing eachother.
Currently direct templates can be created without the required
signatures fields for signers.
This means that the document can be fully signed by everyone but will
ultimately fail the sealing step which leaves the document in an
unrecoverable state.