Quote from: gadamiak at Sep 08, 2011, 06:58 AM
What I want to achieve is serve resources to be secured with a hashed URI, which will expire after a set period. In general I want to achieve what Ligghttpd's ModSecDownload does.
I thought I was clear enough on this (added emphasize to the quote). However, there's a point, which is missing from my description. So to summarize what I want is:
- Secure resources with a hashed URI, which times out after a configurable period. Notice, it's about resources, not files on the server's filesystem.
- Choose resources to be secured based on template property or a TV value (wish there were resource properties).
- Don't alter how MODX handles those resources, which allows to apply ACL methods already supplied by MODX.
So it's not about download (there are extras, which handle that) but about access to MODX resources. Whether they are available publicly or are restricted to a user group is out of scope for this plugin and is handled by MODX access policies or any other logic.
I guess, the plugin should hook to OnPageNotFound system event and compare the resource URI with a reference somehow, or use a custom DB table to store URIs while they are valid. The plugin should also modify the URI of a resource to be secured. What system event would it be, OnWebPageComplete?
The most important is answer to question: How to serve a resource under the secured URI then? It can't just serve a redirect and should disable the "native" resource URI.
I hope I'm clear now.