Like Frogabog says, if you need to restrict access to a file, then this is EXACTLY what Static Resources are for. I'd go even further and say that you should only use Static Resources if you need to do one of the following:
1. Protect the content
2. Search for it using meta-data
Don't reinvent the wheel by making an "Authorization Snippet" -- MODx already can do all of this for you.
First, make sure you have a directory set up for this that is OUTSIDE of the webroot. You need to make sure that nobody can navigate to the PDF in a browser. If you don't have access to any folders that are outside of webroot (e.g. if your host doesn't allow it), then you can also achieve a similar effect by using .htaccess to prevent any access to the special protected directory. (Look at the sample ht.access file in your core directory for an idea of how to do this.
Second, set up a login portal following the tutorial here:
http://rtfm.modx.com/display/ADDON/Login.Basic+Setup
You'll want to set up a members-only area and then add the Static Resources to that special "Members Only" resource group.
The idea is simple: instead of your browser pulling the PDF file directly, instead it requests a PHP page (thru MODx), and MODx streams the file through PHP. The end user has no idea where that file came from because they can only see the end result, not the PHP that generated it. Because streaming files can take a lot of resources, I only use this when I have to. Your situation sounds like the perfect use-case for why you would want to use Static Resources.
[ed. note: Everettg_99 last edited this post 13 years, 8 months ago.]