WPGO Plugins

Protected delivery guide

DocToucan documentation · Free and Pro editions

Protected delivery

Move protected copies outside the public web root and authorize every delivery request.

Protection workflow

  1. Select the Attachment Document and protect its file.
  2. DocToucan copies the source into protected storage and records an immutable manifest.
  3. Assign role, user, password, owner, purchaser, expiry or review policies as required.
  4. Public actions use an expiring signed DocToucan route instead of the Media URL.

Authorization and revocation

Signatures bind document, user, expiry, storage token and generation. Wrong-user, expired and tampered requests fail. Activating another version or rotating links revokes earlier URLs.

Recovery

Restore to public storage only after preflight confirms the source, destination and collision state. Never describe a hidden listing or a public origin URL as protected delivery.