On sign, the route reads required_sections off the contract row, walks each entry, and returns a 409 with 'Please initial every section (missing: <title>)' if any is absent or has no image. Only when all are present does it build the stored map with per-section timestamps and write the signature.
Also called: can't bypass initials · server validation · incomplete waiver rejected
- 1Required sections are read from the contract row, never from the request.
- 2Each entry must have a non-empty image; the stored `at` falls back to now if the client didn't send one.
- 3The rebuilt map — not the client's object — is what gets persisted.
- 4The same route also enforces that the contract is in a signable status and rate-limits to 5 submissions per minute per IP.
Stated in the route: 'if this contract froze a required_sections manifest (e.g. the GCS 13-clause waiver), EVERY listed section must have a non-empty initial. Never trust the client gate alone — re-validate here.' A UI-only gate is not evidence.
- Client-side-only validation on a legal acknowledgment
- Trusting a submitted payload to define its own requirements
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →