Stored documents now protected from direct access

DocVault 1.5.6: stored documents are now protected from direct access

DocVault serves documents through its own download and view links, which check each document’s access settings and expiry date before sending the file. Version 1.5.6 closes a gap: the stored files themselves, in /wp-content/uploads/trdv-documents/, could also be downloaded straight from their storage address by anyone who knew or guessed it, skipping those checks.

What changed

  • On Apache servers, DocVault now writes rules to an .htaccess file in its upload folder that refuse all direct web requests, for both Apache 2.2 and 2.4. Existing sites are protected automatically when they update, and the rules are rewritten whenever the plugin is activated or updated.
  • The same protection covers the legacy sdm-documents folder, if your site has one from an early version of the plugin.
  • A new Site Health check (Tools → Site Health) tests each DocVault upload folder by requesting a stored file from your site as an anonymous visitor would. Only a 403 Forbidden response counts as protected.
  • If files can be downloaded directly, administrators see a warning on DocVault admin screens with the exact rule to add. The warning goes away once the check passes.

If your site runs on Nginx

Nginx ignores .htaccess files, so DocVault cannot add the rule itself. Add this to your site’s server block and reload Nginx, or ask your host to add it:

location ^~ /wp-content/uploads/trdv-documents/ { deny all; }

If your site has a legacy sdm-documents folder, add the same rule for that folder. Site Health shows the exact rule for your site’s upload path. See the troubleshooting guide for more detail.

Update now

1.5.6 is a recommended update for all DocVault users. Update from Plugins in your WordPress admin as usual, then open Tools → Site Health to confirm your documents are protected. New to DocVault? Download it free from WordPress.org.