Protected directory security
Gating only works if visitors cannot reach the file another way. AcquisitionSuite protects uploaded files at three levels.
1. A protected folder
Uploaded files are stored in wp-content/uploads/acquis-protected/, not in the normal media library, and are never listed in the Media screen or in search.
2. Direct access is blocked
On Apache and LiteSpeed, a .htaccess file in that folder disables directory indexing and denies all direct requests. Files are only ever served by AcquisitionSuite itself, after a valid signed token is presented.
3. Signed, single-use, expiring links
The link a lead receives contains a random token, not a file path. It works once and expires after the configured time.
Nginx and other servers
.htaccess rules are ignored by Nginx. If your host runs Nginx, ask them (or add a server rule) to deny public access to the acquis-protected folder. Test it by opening a file’s direct URL in a private window: it should return an error, not the file.
Other safeguards
- Only the allowed file types can be uploaded.
- Every admin action and every form submission is nonce-verified.
- Forms are protected by a honeypot and a rate limit.
- Only users with the
manage_optionscapability (administrators) can manage the plugin. See Roles and permissions.
URL-gated files
An external URL is only as private as the link itself. Anyone who has the raw Google Drive or Dropbox link can open it directly, so use links that require a signed-in account or expire on their own if that matters.