Never Expose Private Storage Paths
When users upload project files or starter code ZIPs, storing them in a public disk allows unrestricted hotlinking and bypasses authorization.
Always store protected resources on the local private disk:
PHP
$path = $request->file('starter_zip')->store('resources/starters', 'local');Authorizing Downloads via Controllers
Create an authorized route that checks the user's permissions before streaming the file:
PHP
public function download(Resource $resource)
{
Gate::authorize('download', $resource);
return Storage::disk('local')->download(
$resource->file_path,
$resource->title . '.' . pathinfo($resource->file_path, PATHINFO_EXTENSION)
);
}This prevents IDOR vulnerabilities and guarantees access logs remain accurate.