Is It Possible to Restrict Access to the GET_FILE Service Beyond Content Server Permissions? (Doc ID 869449.1)

Last updated on FEBRUARY 01, 2017

Applies to:

Oracle WebCenter Content - Version 10.1.3.3.3 and later
Information in this document applies to any platform.
***Checked for relevance on 29-Aug-2011***


Goal

Is it possible to restrict access to the Idcservice GET_FILE beyond the normal Content Server permissions?

One reason this behavior may be desired is if local folders are being used with some of your sites and these local folders contain public content which can be downloaded that may contain sensitive information (e.g. ASP and .NET pages with connection strings). A web server will render the content before it is displayed, thereby keeping it secure, but the GET_FILE Idcservice call will allow users to download the actual file.

Solution

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms