Deletion, storage and security

Protect administrator upload paths

Use the module uploader instead of writing arbitrary paths.

Audience: CRM staffPermission: Appropriate Licence Applications permissionModule v1.0.0
Exact navigationAdmin Area → Licence Applications → Case → Upload Document
Before you begin
  • Use the exact navigation above and confirm the intended invoice, case, client, property, document or environment.
  • Confirm module activation and the stated permission before attempting the action.
  • Use a controlled test record for payments, emails, public/portal access, provider calls and deletion.

What this guide covers

Use the module uploader instead of writing arbitrary paths. These instructions follow the supplied module’s live hooks, menus, controllers, forms, model rules and downstream effects.

Exact step-by-step process

  1. Open the case or storage/audit area described.
  2. Confirm the intended record and visibility.
  3. Perform only the authorised action.
  4. Verify the register, portal and retained evidence after the action.

Fields, choices and supported possibilities

Traversal handlingDownload resolver strips ../ and ..\
Category/help-centre/category/licence-applications/
Topic/help-centre/topic/licence-applications-deletion-security/

Code-backed validations and workflow rules

  • The module applies the stated soft-delete, ownership, visibility or storage behaviour.

Expected result and verification

  • Protect administrator upload paths completes through the supplied module flow.
  • Reopen the source record or settings page and verify the stored value, status, payment, file, timeline entry or notification.

Security, privacy and operational checks

  • Do not expose landlord, property, identity or authority documents beyond their intended audience.
  • Do not delete storage files directly to simulate a module action.