Download to a directory that only the download process can read/write.
Upon completion, cp the file to a world read directory.
This is a general solution for production systems and requires different user groups, and a background process that can perform the cp.
|