Computer-implemented procedure, executed by a
sync client (320), which includes: Receiving a request from a first application on a local device (302) to open a document which has a
document identifier and is associated with a first file stored on a
server (206), wherein the request includes the
document identifier and a
user identifier; Determine that a second file stored on the local device (302) is associated with the
document identifier and that a user associated with the
user identifier is authorized to access the second file; Sending (524) a
list comprising one or more applications that are on the local device (302) and that are capable of opening the second file, based on the determination to the first application; Receiving (534) a specification of a second application selected from the
list (528), from the first application; and Sending (536) a message to open the second file with the second application; including determining whether the user is authorized to access the second file: Received (606) from the first application, an
authentication request containing an initial one-time key; Calculate (608) an
initiation hash based on the first one-time key and a pre-shared key; Sending the
initiation hash to the first application for
verification; Received (614), from the first application, of an acknowledgment hash; and Verify (616) that the confirmation hash matches an independently calculated confirmation hash; wherein the first application is a browser (312) or a browser extension (324) associated with the browser (312).