Its possible to externally set comments to files and even templates to folders..
so why not be able to set folder restrictions for up and download defined in hfs.settings.ini.
This also makes it able to set upload rights in a sub folder inside a real folder, instead of giving upload rights to the entire real folder.
btw, i discovered that when you enter
http://host/folder/hfs.diff.tpl, you can actually download the diff template. I think that that, along with hfs.settings.ini, should be restricted and give a 4.04 error. (or access denied error, tho 4.04 is better for security reasons)