❓ Error message "Access denied" for transfers
Problem: "Access denied" error message for transfers
A user attempts to open an FTAPI transfer via a notification link in an email. Although the user has access to the email mailbox (e.g., a shared team mailbox or a substitute mailbox), access is denied and the "Access denied" error message is displayed.
Cause: Strict recipient binding in FTAPI
For security reasons, FTAPI transfers are bound to the email address of the original recipient. When an access attempt is made, the system checks whether the logged-in FTAPI user matches the stored recipient of the transfer. If this is not the case, access is denied.
Example: A transfer is sent to info@firma.de. Ms. Meier, who has access to this mailbox, clicks the link and logs in with her personal FTAPI account meier@firma.de. Since her account does not match the recipient (info@firma.de), access is blocked.
Affected security levels
This security check applies to all security levels that require a login to the FTAPI system.
- Security level 1 (Secure link): This level is not affected. No FTAPI account is required for the download, so anyone with the link can access the files.
- Security levels 2, 3 and 4: These levels are affected. Access strictly requires a login with an FTAPI account whose email address matches that of the recipient. This triggers the "Access denied" error message if another person attempts to access it.
Solution: How to gain access to the transfer
To access the content, there are two possible solutions:
- The original recipient logs in: The person assigned to the original recipient mailbox (in the example, this would be the user for
info@firma.de) must log in with the corresponding FTAPI account to open the transfer. - Resend the transfer: The sender must resend the transfer, but this time directly to the personal email address of the user who needs access (e.g., directly to
meier@firma.de).
More about FTAPI security levels