Understand denied attachment extensions
Know security deny-list.
Exact navigationAutomatic attachment validation — no separate menu route
What this guide covers
Know security deny-list. The workflow below follows the supported application or module flow and does not invent a menu or bypass validation.
Exact step-by-step process
- Open the exact navigation path shown above.
- Select the authorised mailbox, message or configuration record.
- Complete the fields or action described in this guide.
- Save or submit once, then verify the resulting status and related record.
Fields, choices and supported possibilities
This workflow does not expose additional user-entered fields.
Code-backed validations and workflow rules
- Denied includes php/phtml/pht/phar/cgi/pl/py/rb/sh/bash/zsh/js/mjs/html/htm/xhtml/shtml/htaccess/ini/env/log/exe/dll/so/dylib/com/bat/cmd/msi/jar/ps1/vbs.
- Unknown unsafe names can become .bin.
- Deny-list applies even with broad allow-list.
Expected result and verification
- The requested Mailbox Exchange record is updated through the supported controller and remains attributable to the acting staff member.
Security, audit and troubleshooting checks
- Use the exact authorised account, role and record before saving or sending.
- Verify the saved status and downstream record; a browser success message alone is not sufficient evidence.
- Never expose passwords, API keys, access tokens, protected attachments or raw server paths in support tickets.
- Do not edit module or core database records directly to bypass validation, permissions, migrations or state rules.
