[ ] Fix docker mapping of drupal-private. It should be drupal-private:/var/www/private. Make sure to copy any files from /var/www/web/private to /var/www/private
[ ] Review file upload directories to see which can be made private.
[ ] Test that uploaded private images, documents etc are not publicly accessible
For example, the Sector Plan Map media type in Forests should set upload destination to Private. It is currently public. https://forests.ddev.site/admin/structure/media/manage/sector_plan_map/fields/media.sector_plan_map.field_media_image Check the upload destination of all Farmers image and other media settings