Download not allowed
The download landing page is replaced with a Download not allowed screen (whitelist title). The file owner has an IP whitelist, and the current client IP is not on it.
Why this happens
SSR gate when the owner is the signed-in party (or whitelist applies) and clientIpPassesUserIpWhitelist fails. Related API streams may return a whitelist IP error string. Different from extension allowlists or geo country blocks.
Diagnose and fix
1. Admin → Users → Whitelisted IPs for that owner — add the viewer’s public IP, or clear the list to stop restricting.
2. Confirm proxy forwards the real client IP.
3. Owner testing from another network must add that IP too.
4. Distinct from Uploads not available from your region / download geo blocks.