Safe File Handling
Learn how to serve files safely.
We'll cover the following
Back to our story
Circling back to Erica’s story: if you have documents that are served to your users for viewing or downloading, you can’t simply set access control on the *.pdf
files. Why not? See, I knew you were going to ask that. It helps that I’m the narrator here.
What you need to do is store the file on your server where it can not be accessed from your web server. Here’s one example of a recommended directory structure:
Get hands-on with 1400+ tech skills courses.