We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 36541
    • 222 Posts
    I'm in a need to secure access to static resources from off-site downloads. There are some server side tricks, but I'm looking for a MODX native way, which would be more flexible and manageable.

    What I want to achieve is serve resources to be secured with a hashed URI, which will expire after a set period. In general I want to achieve what Ligghttpd's ModSecDownload does.

    I guess, that's a job for a plugin. I think, it might be useful also for regular resources or payable content.

    I need advice how to approach this.
      This is the web: the only thing you know about who will come is that you don't know who will come.
      • 36541
      • 222 Posts
      Any suggestions?
        This is the web: the only thing you know about who will come is that you don't know who will come.
        • 10449
        • 956 Posts
        It depends a bit... what's the big picture?

        a) time-limited download, for everyone the same limit?

        or

        b) time-limited download on a per-user (account) basis? e.g. user X purchased a subscription between A and B, and can download everything within that period

        In any case, you'd want to store your files outside the web-root (beneath public_html or whatever it's called on your server). The only way to view / download any of your files would be via a PHP script / snippet, that "grabs" the desired file sets the correct headers, and echo()s the contents. That - or create ZIP archives from one or several files.

        Finding a solution for scenario a) would be relatively easy. A solution for b) definitely needs more work - but most importantly - a clean description of how things are supposed to work. Especially if stuff like online payments are also involved. Can you elaborate?
          • 36541
          • 222 Posts
          Quote from: gadamiak at Sep 08, 2011, 06:58 AM

          What I want to achieve is serve resources to be secured with a hashed URI, which will expire after a set period. In general I want to achieve what Ligghttpd's ModSecDownload does.

          I thought I was clear enough on this (added emphasize to the quote). However, there's a point, which is missing from my description. So to summarize what I want is:


          • Secure resources with a hashed URI, which times out after a configurable period. Notice, it's about resources, not files on the server's filesystem.
          • Choose resources to be secured based on template property or a TV value (wish there were resource properties).
          • Don't alter how MODX handles those resources, which allows to apply ACL methods already supplied by MODX.

          So it's not about download (there are extras, which handle that) but about access to MODX resources. Whether they are available publicly or are restricted to a user group is out of scope for this plugin and is handled by MODX access policies or any other logic.

          I guess, the plugin should hook to OnPageNotFound system event and compare the resource URI with a reference somehow, or use a custom DB table to store URIs while they are valid. The plugin should also modify the URI of a resource to be secured. What system event would it be, OnWebPageComplete?

          The most important is answer to question: How to serve a resource under the secured URI then? It can't just serve a redirect and should disable the "native" resource URI.

          I hope I'm clear now.
            This is the web: the only thing you know about who will come is that you don't know who will come.
            • 18373 ☆ A M B ☆
            • 3,141 Posts
            Mark Hamstra Reply #5, 15 years ago
            Bit of a late response I suppose, but if you're still working on that some quick thoughts:

            You can forward (not redirect) a request with
            $modx->sendForward($resourceid);

            from the onpagenotfound event.

            You can also override the URI of the resource with a random hash and set an unpublishdate?
              Mark Hamstra • Developer spending his days working on Premium Extras and a MODX Site Dashboard with the ability to remotely upgrade MODX and extras to make the MODX world a little better.

              Tweet me @mark_hamstra, check my infrequent blog at markhamstra.com, my slightly more frequent ramblings at MODX.today or see code at Github.
              • 36541
              • 222 Posts
              Better late than never smiley

              I've put it on hold for now, but I'll rather have to go back to it in the future. Thanks for your suggestions, Mark.
                This is the web: the only thing you know about who will come is that you don't know who will come.