Synthetic Industry

Troubleshooting guide · updated 2026-10-11

Add a private order-document download without publishing the whole storage folder

Define purchaser permission, storage location and expiry as separate controls for a new Laravel document-download feature.

Agree who may receive the document

For a new download feature, define whether the purchaser, a named organisation administrator or another approved role may download each order document. Decide how revoked or cancelled access works. A user being logged in does not establish permission for a particular order, and knowing a filename is not an authorization rule.

  • Use synthetic order documents and two disposable accounts in the preview.
  • Keep the file-to-order mapping server-owned; do not accept arbitrary storage paths from the browser.
  • State whether a link is a shareable bearer capability or requires an authenticated policy check.

Storage visibility and URL expiry answer different questions

Laravel distinguishes its private local disk from the public disk intended for web-accessible files. Creating a public storage symlink is not an appropriate fix for private invoices. A download response sets delivery behaviour; a temporary URL gives an expiry. Neither, by itself, proves that the correct person was authorised when the application issued access.

  • Check the existing application's actual disk configuration; defaults can differ across versions and customised projects.
  • Do not paste a real temporary URL into an enquiry or log its signature.
  • Explain revocation and cache limitations before relying on expiry for sensitive content.

Acceptance includes someone who must be denied

An authored test permits account A's agreed document and denies account B's corresponding unauthorised request. Test direct URL/path attempts on the isolated copy, an unknown document and an expired disposable link where links are used. Keep the status and synthetic identity labels, not the actual secrets. No protected download has been implemented or exercised here.

  • A hidden button is not a server-side denial test.
  • Check that the response and storage setup do not expose unrelated files.
  • Agree how a legitimate customer requests help after expiry without receiving another person's document.

Non-fit, safety and priced route

Invoice, customer-document or personal-data access changes need a separate security review and separately agreed scope; they are not included in the ordinary £750 feature offer merely because a preview uses synthetic documents. Only a qualifying small download feature that changes neither payment nor personal-data handling may fit ship-one-feature-with-running-preview, from £750. That requires agreed criteria, a fixed quote, an existing isolated, private, access-controlled and time-limited preview route, and two revision rounds; payment follows passing checks and the buyer's sign-off. A whole document-permission system, new storage account, financial-record migration or regulatory assessment requires separate scope. If live private documents may already be public or accessible across accounts, use the customer's security incident route first; the ordinary £295 bug offer explicitly excludes disclosure handling.

  • No live customer documents, storage keys, account creation or publication is authorised by this guide.
  • The proposed price is not a proven customer acceptance or previous-delivery claim.

Sources and limits