File Extension Whitelist

Was this article helpful?

The File Extension Whitelist global feature lets you define the file extensions that users are permitted to upload or file across Clio Operate. When the feature is enabled and configured, Clio Operate enforces the allowlist in the Outlook Add-in, document repository uploads, drag-and-drop filing, inbound filing, and Virtual Data Rooms.

Users who attempt to upload or file a disallowed file type receive an error message advising them to contact their system administrator.

Access this global feature at Launchpad > Modeller > Global Features. Search for File Extension Whitelist. The feature is listed under the Security category.

Configure the allowlist

  1. Select the Configure button on the File Extension Whitelist feature card.
  2. In the Allowed File Extensions field, enter the file extensions you want to permit.
  3. Select Save.

The configuration supports standard import and export. Use the import and export buttons on the feature card to transfer the allowlist between environments.

Allowed File Extensions field

Enter extensions as a comma-separated list without leading dots, for example: pdf, docx, jpg. The check is case-insensitive, so PDF and pdf are treated as the same extension.

Pre-seeded extensions

The allowlist is pre-seeded with a standard set of extensions when the feature is first enabled:

.pdf, .doc, .dot, .docx, .docm, .dotx, .dotm, .rtf, .ppt, .pot, .pps, .pptx, .pptm, .potx, .potm, .ppsx, .ppsm, .vsd, .vsdx, .vsdm, .vdx, .odt, .ott, .fodt, .ods, .ots, .fods, .odp, .otp, .fodp, .odf, .odg, .otg, .fodg, .dwg, .dxf, .dwf, .dgn, .html, .htm, .xhtml, .xhtm, .msg, .eml, .txt, .csv, .dcm, .dicom, .dcim, .dicm, .tif, .tiff, .jpg, .jpeg, .jp2, .jpc, .gif, .png

You can add or remove extensions to match your organisation's requirements. DICOM (.dcm, .dicom) is included by default to support clients who work with medical image formats.

Where the allowlist is enforced

Once configured, Clio Operate checks the allowlist in the following areas:

  • Outlook Add-in - attachments with disallowed extensions do not appear in the File Attachments list. A message advises users to contact their system administrator if they expect an attachment to be present.
  • Document repository upload - users cannot upload a disallowed file type. The file explorer filters to show only permitted extensions by default. If a user selects All Files to bypass this filter and attempts to upload a disallowed file, the server rejects it and displays an error.
  • Drag-and-drop filing - dragging a disallowed file into the DMS widget triggers an upload failure message.
  • Inbound filing - disallowed attachments on inbound emails are blocked during the filing process.
  • Virtual Data Rooms - uploads via the VDR interface follow the same rules as document repository uploads.

Was this article helpful?

Related Articles

Related articles in the knowledge base