The two byte sources for the executed artifact

FeatureDocsService
Shipped
August 6, 2026 at 8:41 PM UTC
Author
Kamo
Commit
0d48436

LegalPinnedPdf extracts the frozen-digest rule out of the member read path so the wizard and the filed artifact read the SAME bytes through the SAME check — contentSha256 hashes the img_dats content-address triple, so the comparison costs no MinIO read and differs if and only if the bytes moved, and saveImgContent repoints img.setDat on every Docs save. Modifications are applied, because that is what the member was shown. **************** reads the FLATTENED PDF from the service that produced it. Nothing in ESigService changes: the internal endpoint already exists behind the same X-Internal-Auth + X-Org-Id pair. Re-flattening here would be a second set of signature-placement bugs over bytes ESigService has already committed to. 404 comes back as an empty Optional rather than an exception. EsignPublicService wraps flatten in try/catch { log.error }, so an envelope can sit SIGNED with a null signedBlobId forever — that is exactly what EXECUTION_INCOMPLETE names, and the caller refuses to merge an artifact missing a signature page.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing