Thank you for your answer.
I can’t see how downloading a file with “a href” is different security-wise from placing it in an “img src” tag in customer area , but I’m not going to argue here, it’s your software.
PS. the code blocks don’t work on this froum