I’ve actually been using Static Resources, but I’ve just been grabbing the content via a script and then using my own code for the download. I hadn’t though about actually going to the the Static Resource URL. I went ahead and tried this approach as you suggested, but I wasn’t successful. It tried to download an .htm file instead of the file referred to by my Static Resource.
Here’s a short screencast illustrating my attempt.
EDIT:
Ok, I just realized that the content type probably has to match the download type, but there is not content type for an .flv file and I can’t find where this list is populated from. Also, why not just have the content type determined by the file extension automatically?
If I am able to get the Static Resources working via a URL - how can I protect that URL so that only authorized users can access the download? I’m thinking that I would use a plugin for that, but I’m not sure what the most efficient method would be. Perhaps something like:
if (page is a static resource) {
Get resource groups associated with this static resource;
Compare resource groups with user membership level
if (ok) {
keep going
}
else {
Figure out referring page
send back to this page with a header
]
When a member is logged in, their access level(s) are saved in a SESSION variable. So, for every protected resource the access levels of the member have to be checked against the resource groups of the resource. So, if a Static Resource is in the resource groups church, member and individual, and the user is associated with the user group "individual" than access is allowed.