Documents, MIME validation and secure downloads
Upload supported evidence, store it in module records/BLOB storage and enforce ownership/visibility on downloads.
Service Journeys
Open guide →GuideUpload a staff document
Choose document type, file, notes and client visibility.
Open guide →GuideUpload a client document
Choose a document type, file and notes from the owned journey; client uploads are visible.
Open guide →GuideComplete Document type
Required, maximum 191 characters.
Open guide →GuideComplete Document notes
Add useful context.
Open guide →GuideSet document visibility
Staff can choose Visible to client; client uploads are stored as client-visible.
Open guide →GuideUnderstand allowed file extensions
PDF, DOC/DOCX, XLS/XLSX, PNG, JPG and JPEG are supported.
Open guide →GuideUnderstand MIME validation
The controller verifies accepted type information instead of relying only on the filename.
Open guide →GuideUnderstand the 10 MB file limit
Uploads larger than 10 MB are rejected.
Open guide →GuideUnderstand document storage
Document file content is stored in the module database record/BLOB workflow.
Open guide →GuideDownload a document as staff
Use the secure controller action from the case.
Open guide →GuideDownload a document as a client
The document must belong to an owned journey and be visible to the client.
Open guide →GuideUnderstand secure download headers
Downloads use attachment disposition, nosniff and no-store controls.
Open guide →GuideResolve a missing document
Check record, ownership, visibility and stored content.
Open guide →GuideResolve invalid type or size
Use a supported extension/MIME and a file no larger than 10 MB.
Open guide →