To avoid external access to the DMS directory it has to be protected with .htaccess. A download via the DMS functions is still possible, but the upload is denied. To offer this, the upload should be send to the Contao tmp directory and moved afterwards to the DMS directory.