> Regardless you should validate that the passed path falls in the
> "browsable" root dir
> doing that, it shouldn't really matter if the user sees it or not.
> If the dir isn't supposed to be seen, don't show it!
I think that is the most obvious way doing it I just didn't really figure
out how to do it yet ....