View Categories

Client Uploads and File Security

1 min read

Clients can send certificates, photographs, GEDCOM files and documents with their intake form. The plugin treats those files as confidential.

What can be uploaded #

  • File types: GEDCOM (.ged), PDF, JPG and JPEG, PNG, GIF, Word (.docx) and plain text (.txt).
  • Size: up to the Largest upload in Settings - 20 MB unless you change it - or your server's own limit, whichever is lower.
  • Each file is checked by what it actually contains, not just its name. A file whose contents do not match its name is refused.

If a file is refused, the client is told which file and why - too large, the wrong kind, empty, or not what its name says.

Where the files are kept #

Uploads are stored in their own folder inside your uploads directory (wp-content/uploads/ap-casework-manager/), one folder per engagement, under long random names. They are not in your media library and the plugin never shows their addresses. You open them from the engagement's Intake tab, and the plugin hands them out only to you.

Checking the folder is closed to the web #

The plugin writes a rule into that folder telling the web server to refuse direct requests. Apache follows it; nginx ignores it. So rather than assume, the plugin measures: once a day your site requests a test file from itself and records whether it was refused. The result is under Keeping records in Settings, and Check again measures it now.

If the folder is open, the dashboard warns you and shows the line to add to your nginx configuration - location ^~ /wp-content/uploads/ap-casework-manager/ { deny all; } - or ask your host to block web access to that folder. If the site could not reach itself to test, the result is reported as unknown, never as protected.