HTTP security
From the Apache HTTP Server manual:
It is important to never use
<Location>
when trying to restrict access to objects in the filesystem. This is because many different webspace locations (URLs) could map to the same filesystem location, allowing your restrictions to be circumvented.
Apparently, (1) the same thing applies to Microsoft IIS and (2) our IT department is not aware of it.