netdoc: is an old Java URL handler that resolves to a local file read. It predates and parallels file:, and because defenders often blocklist file:// while forgetting netdoc:, it is a useful alternative for reading local files on a JVM stack.
Reading a file#
The handler takes a path much like file::
netdoc:/etc/passwd
netdoc:///etc/passwd
netdoc:/proc/self/environ
On a Java client that still exposes the handler, this returns the file contents through the same channel that reflected the fetch, reaching the same targets as the File scheme: configuration with credentials, environment, source, and keys.
Why it exists as a separate page#
The only reason to use netdoc: over file: is evasion. A scheme allowlist or blocklist written for http/https/file commonly omits the legacy handler, so when file:// is rejected but the stack is Java, netdoc: reaches the filesystem anyway. It belongs in the rotation alongside File and JAR: when one Java-reachable local scheme is filtered, try the others before concluding local read is unavailable.