We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 37108
    • 80 Posts
    I understand how to create members-only pages, but what does one do when it comes to protecting PDFs (or other files)? For example if someone types the url www.example.com/articles/file.pdf to get file.pdf, there's no way to restrict access to a certain user group by way of modx-only logic, correct?

    My initial concept to solve this is to have an apache redirect that sends anyone accessing /articles/*.pdf to a modx page that runs an authorization snippet. If the user is logged in with correct creds, they would be directed back to get the file. Otherwise, they'd be sent to an unauthorized/login page. Make sense?
      • 10208 ☆ A M B ☆
      • 1,780 Posts
      You can make your document a static resource and put it in your private resource group. Set the content type to pdf, and content disposition to attachment.

      Prior to doing that, make the pdf content type under file menu System -> Content Types

      Name: PDF

      Desc.: PDF Content

      MIME Type: application/pdf

      File extension: .pdf

      Binary: yes
        Frogabog- MODX Websites in Portland Oregon
        "Do yourself a favor and get a copy of "MODX - The Official Guide" by Bob Ray. Read it.
        Having server issues? These guys have MODX Hosting perfected - SkyToaster
        • 9207 ☆ A M B ☆
        • 2,475 Posts
        Like Frogabog says, if you need to restrict access to a file, then this is EXACTLY what Static Resources are for. I'd go even further and say that you should only use Static Resources if you need to do one of the following:

        1. Protect the content
        2. Search for it using meta-data

        Don't reinvent the wheel by making an "Authorization Snippet" -- MODx already can do all of this for you.

        First, make sure you have a directory set up for this that is OUTSIDE of the webroot. You need to make sure that nobody can navigate to the PDF in a browser. If you don't have access to any folders that are outside of webroot (e.g. if your host doesn't allow it), then you can also achieve a similar effect by using .htaccess to prevent any access to the special protected directory. (Look at the sample ht.access file in your core directory for an idea of how to do this.

        Second, set up a login portal following the tutorial here: http://rtfm.modx.com/display/ADDON/Login.Basic+Setup
        You'll want to set up a members-only area and then add the Static Resources to that special "Members Only" resource group.

        The idea is simple: instead of your browser pulling the PDF file directly, instead it requests a PHP page (thru MODx), and MODx streams the file through PHP. The end user has no idea where that file came from because they can only see the end result, not the PHP that generated it. Because streaming files can take a lot of resources, I only use this when I have to. Your situation sounds like the perfect use-case for why you would want to use Static Resources. [ed. note: Everettg_99 last edited this post 13 years, 8 months ago.]
          • 40131
          • 40 Posts
          The easiest way to solve your problem is to use fileLister:

          http://rtfm.modx.com/display/ADDON/FileLister

          It has file link hash protection and logged users only download.