We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 18654
    • 191 Posts
    Does anyone have any ideas on how to restrict access to files such as .pdf and .doc? I’m thinking it would have to be through apache .htaccess because if the file is located in: domain.com/assets/media/file.pdf then the ModX framework is bypassed when this URL is directly requested and there’s no opportunity to run a php script since the file extension is .pdf.

    What I’m trying to do is allow access to documents based on whether a user is logged in. If they are logged in, they can view the document. The other thing I thought about was placing the files outside of the web root but that introduces other problems - as far as I can tell there’s no way to open the pdf in the web browser this way. Also, I can’t make http requests for my video files this way.

    The thing I can’t figure out with apache is how I would pass authentication status from a php session variable to apache. Also, I know very little about writing apache code.
      God does not save those who are only imaginary sinners. Be a sinner, and let your sins be strong, but let your trust in Christ be stronger, and rejoice in Christ who is the victor over sin, death, and the world.
      • 20413
      • 2,877 Posts
        @hawproductions | http://mrhaw.com/

        Infograph: MODX Advanced Install in 7 steps:
        http://forums.modx.com/thread/96954/infograph-modx-advanced-install-in-7-steps

        Recap: Portland, OR (PDX) MODX CMS Meetup, Oct 6, 2015. US Bancorp Tower
        http://mrhaw.com/modx_portland_oregon_pdx_modx_cms_meetup_oct_2015_us_bancorp_tower
        • 18654
        • 191 Posts
        Quote from: mrhaw at Oct 17, 2009, 12:39 AM

        See this thread http://modxcms.com/forums/index.php/topic,37280.msg225043.html#msg225043

        But also check out http://www.php-mysql-tutorial.com/wikis/mysql-tutorials/uploading-files-to-mysql-database.aspx
        (I haven’t used this code but the idea is cool!)

        Thanks for the quick response! It seems like the snippets in the extras section are not available for Revolution. However, I did finally figure out what I needed to do on the php side - in order to get the content to display in the browser I had to change "Content-Disposition" from "attachment" to "inline." So, the code below works. Now I just have to figure out how to use .htaccess to deny all web requests to certain directories while still allowing access to my php scripts. Any ideas on this? Also, is there anyway to secure a streaming video source so that it will only stream to logged-in users?

        <?php
        
        	$getfile = 'myfile.pdf';
        	$filepath = 'somepathinfo'.$getfile;
        	 
          	// check that it exists and is readable
          	if (file_exists($filepath) && is_readable($filepath)) {
        		// get the file's size and send the appropriate headers
        		$size = filesize($filepath);
        		//header('Content-Type: application/octet-stream');
        		header('Content-Type: application/pdf');
        		header('Content-Length: '.$size);
        		header('Content-Disposition: inline; filename='.$getfile);
        		header('Content-Transfer-Encoding: binary');
        		// open the file in binary read-only mode
        		// suppress error messages if the file can't be opened
        		$file = fopen($filepath, 'rb');
        	}
        	
            if ($file) {
        	  // stream the file and exit the script when complete
              fpassthru($file);
              exit;
              }
        
        ?>
        
        
        


        -matt
          God does not save those who are only imaginary sinners. Be a sinner, and let your sins be strong, but let your trust in Christ be stronger, and rejoice in Christ who is the victor over sin, death, and the world.
          • 22303 MODX Staff
          • 10,725 Posts
          Quote from: mattcdavis1 at Oct 17, 2009, 02:28 AM

          Now I just have to figure out how to use .htaccess to deny all web requests to certain directories while still allowing access to my php scripts. Any ideas on this?
          To prevent direct web requests but still allow your php scripts to access the files, you can simply do something like this in .htaccess:
          IndexIgnore */*
          <FilesMatch "\.(pdf|doc)$">
              Order Deny,Allow
              Deny from all
          </FilesMatch>
          

          You can see more discussion of this at http://www.askapache.com/htaccess/using-filesmatch-and-files-in-htaccess.html
            • 18654
            • 191 Posts
            Perfect - Thanks!
              God does not save those who are only imaginary sinners. Be a sinner, and let your sins be strong, but let your trust in Christ be stronger, and rejoice in Christ who is the victor over sin, death, and the world.