Agree who may receive the document
For a new download feature, define whether the purchaser, a named organisation administrator or another approved role may download each order document. Decide how revoked or cancelled access works. A user being logged in does not establish permission for a particular order, and knowing a filename is not an authorization rule.
- Use synthetic order documents and two disposable accounts in the preview.
- Keep the file-to-order mapping server-owned; do not accept arbitrary storage paths from the browser.
- State whether a link is a shareable bearer capability or requires an authenticated policy check.
Storage visibility and URL expiry answer different questions
Laravel distinguishes its private local disk from the public disk intended for web-accessible files. Creating a public storage symlink is not an appropriate fix for private invoices. A download response sets delivery behaviour; a temporary URL gives an expiry. Neither, by itself, proves that the correct person was authorised when the application issued access.
- Check the existing application's actual disk configuration; defaults can differ across versions and customised projects.
- Do not paste a real temporary URL into an enquiry or log its signature.
- Explain revocation and cache limitations before relying on expiry for sensitive content.
Acceptance includes someone who must be denied
An authored test permits account A's agreed document and denies account B's corresponding unauthorised request. Test direct URL/path attempts on the isolated copy, an unknown document and an expired disposable link where links are used. Keep the status and synthetic identity labels, not the actual secrets. No protected download has been implemented or exercised here.
- A hidden button is not a server-side denial test.
- Check that the response and storage setup do not expose unrelated files.
- Agree how a legitimate customer requests help after expiry without receiving another person's document.
Non-fit, safety and priced route
Invoice, customer-document or personal-data access changes need a separate security review and separately agreed scope; they are not included in the ordinary £750 feature offer merely because a preview uses synthetic documents. Only a qualifying small download feature that changes neither payment nor personal-data handling may fit ship-one-feature-with-running-preview, from £750. That requires agreed criteria, a fixed quote, an existing isolated, private, access-controlled and time-limited preview route, and two revision rounds; payment follows passing checks and the buyer's sign-off. A whole document-permission system, new storage account, financial-record migration or regulatory assessment requires separate scope. If live private documents may already be public or accessible across accounts, use the customer's security incident route first; the ordinary £295 bug offer explicitly excludes disclosure handling.
- No live customer documents, storage keys, account creation or publication is authorised by this guide.
- The proposed price is not a proven customer acceptance or previous-delivery claim.
Sources and limits
- Laravel 12.x filesystem: public/private disks and temporary URLs; MIT-licensed documentation Checked 2026-10-11.
- The default local disk root is storage/app/private in this version's reference.
- The public disk is explicitly intended for public files and its symlink exposes that directory.
- download generates a download response; temporaryUrl adds expiry for supported drivers.
- Laravel 12.x policies and gates Checked 2026-10-11.
- Authentication and permission for a resource are distinct.
- Policies and route middleware can enforce authorization before an action.
- Current one-feature preview scope Checked 2026-10-11.