Safe File Handling

Learn how to serve files safely.

We'll cover the following

Back to our story

Circling back to Erica’s story: if you have documents that are served to your users for viewing or downloading, you can’t simply set access control on the *.pdf files. Why not? See, I knew you were going to ask that. It helps that I’m the narrator here.

What you need to do is store the file on your server where it can not be accessed from your web server. Here’s one example of a recommended directory structure:

Get hands-on with 1400+ tech skills courses.