Help center support eXpress

We've collected answers to popular questions to make eXpress easy and convenient to use. Didn't find the answer to your question? Contact our support team.

Files Security

MIME Type Restrictions in Web/Desktop Apps

In the web/desktop application, you can send any files except those with a prohibited MIME type. Prohibited files may include some executable files, installation files, and scripts.

Do Restrictions Work Based on File Extensions?

No, restrictions work based on content. For example, most executable files with extensions like exe, deb, etc., have allowed MIME types.

What Happens If the File Content Cannot Be Determined?

If the app cannot determine the MIME type of a file, sending it will be impossible. In such cases, contact eXpress support.

Which MIME Types Are Prohibited by Default?

  • application/vnd.microsoft.portable-executable
  • application/x-msdos-program
  • application/x-ms-dos-executable
  • application/x-executable
  • application/x-msi
  • application/x-debian-package
  • application/vnd.debian.binary-package
  • application/x-redhat-package-manager
  • application/x-apple-diskimage
  • application/mac-binhex40
  • application/javascript
  • application/x-javascript
  • application/x-oz-application
  • application/x-sh
  • application/x-shellscript
  • application/x-shockwave-flash
  • application/x-java-archive
  • application/java-archive
  • application/x-xpinstall
  • text/iuls

Can the List of Prohibited MIME Types Be Extended?

ETS
The organization's administrator may additionally prohibit other MIME types. For consultation, contact your organization's support team or eXpress support.

Blocking of Dangerous Content When Viewing PDFs

Starting from version 3.59, in the web and desktop applications, PDF files containing the following content cannot be viewed: HTML script tags, JS methods, DOM access, forms and annotations, and content obfuscation. When attempting to open such a document for preview, the application will display an error “File blocked for security reasons”.

Additionally, when viewing PDFs, the following features are unavailable: JS functions, document navigation, form handling, annotations, and hyperlinks.

Role Model Restrictions for Files

CTS
eCTS
If the role model is enabled and configured on the corporate server, you may encounter warnings such as "This chat has sending restrictions" or other prohibition messages. This means that the chat or channel has restrictions on sending, downloading, or forwarding attachments:
  • by file size, for example: “Forwarding videos over 300 MB is restricted,” “This chat has restrictions on sending documents over 20 MB”;
  • by file type, for example: “Viewing documents is restricted,” “Downloading images is restricted”;
  • by file extension, for example: “Disallowed sending of: docx”, “This chat has restrictions on sending images in this format”;
  • by user type or specific users in the chat, for example: “Images are not allowed to be forwarded into chat with the user ...”;
  • by action type — sharing, viewing, downloading, or forwarding a file may be prohibited, for example: “You are not allowed to forward videos from this chat”, “This chat has restrictions on viewing attachments”.
When download restrictions are active on mobile devices, an built-in document viewer is used.

What Happens If My Attachment Is Prohibited?

Attachments subject to restrictions may be marked with an error icon or accompanied by a corresponding warning. Such attachments can only be deleted (except for attachments created within the app, such as photos — they can be downloaded to the device).

I Renamed the File, but Sending Is Still Blocked. Why?

The app determines the file type by its content, not by the extension in its name. Therefore, renaming does not remove the restriction: a document renamed as an image remains a document and is subject to the same restriction.

Is It Possible to Know About Existing Restrictions in Advance?

For more information about the restrictions, click or tap on the Learn more label or the information button in the pop-up warning.

For a detailed description of all role model restrictions for working with files and their application in chats and Smart Apps, see the section "Role Model Rules".

Contour Restrictions on Sending Files

CTS
eCTS
In the corporate server settings, administrator can restrict file sharing and screen sharing access, allowing it only for users within the contour — the internal corporate data transmission system (CDTS). If contour access is enabled, users from external networks may receive the error “Available only from the company network” when trying to view a file. Users within the contour will not be able to open files from users outside the contour due to the error “You have no access to this file.” To check or configure these restrictions, contact your organization's support team or eXpress support.
When contour restrictions are enabled, sending files to chats with disabled end-to-end encryption (open chats) is prohibited.

Antivirus & DLPS Integrations

CTS
eCTS
The corporate server administrator can enable antivirus scanning of sent files and integration with a DLP system. A file that fails the scan will not be sent. Configuring antivirus scanning and DLP is done in the separate console that manages the integration of the server with the antivirus and DLP system. Detailed information is available in the administrator guide in the Product Documentation section.

Watermark

Starting from server version 3.69 and mobile apps iOS/Android 3.70, an administrator can enable the overlay of a watermark (containing user, time, and device data) on images and videos when they are saved or forwarded from mobile devices — to help trace the source in case of a file leak.