8
In my Symfony 2 project, I have a page displaying information about an entity. On this page there is also a link to a file associated to this entity.
The page is secured and it can be displayed only if the user as a specific role. The expected role is not the same for every entity so it's tested dynamicaly in the Action.
My problem is that even if the page is secured, anyone can access the file via its URL. I'd like it to be downloadable only if the role matches the one for the page display.
Any suggestion on how I should do it, or where to start looking ?