We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 8822
    • 203 Posts
    Hi,

    Does anyone how to restrict access to a webpage, based on the referring URL. For example, if a user comes from www.referringurl.com then they should be able to view the page, if they don't then they should be re-directed elsewhere.

    To give you an idea of the situation, i have integrate worldpay into MODX for payment of a single product. If the transaction is successful Worldpay displays a page with a direct URL to the 'download' page for the product they just bought. I would like to restrict who can view this download page based on where they have come from (i.e. which URL - worldpay).

    Using Revo 2.2.6
    Thanks!
      • 42562
      • 1,145 Posts
      Are you looking for something like this? Try and see what happens
      $redirect_url = $modx->makeUrl(337); //337 is id of destination page where you want unwanted folk directed to
      $present_url = $_SERVER['HTTP_REFERER']; //where user is coming from
      $site_url = $modx->config['site_url']; //your site's full url
      $worldpay_url = "".$site_url."worldpay.html"; //url of worldpay to be matched
      
      if ($present_url !== $worldpay_url) // if referring url does not match worldpay.html...
      {
      $modx->sendRedirect($redirect_url); // ...please get lost, go to page 337
      die();
      }
      Create this snippet, check_url and call it in download.html, [[!check_url]]. Alter the url names inside...
      Note, although the common user would suffer this redirection mandate, an advanced user can fake his or her referring url.
        TinymceWrapper: Complete back/frontend content solution.
        Harden your MODX site by passwording your three main folders: core, manager, connectors and renaming your assets (thank me later!)
        5 ways to sniff / hack your own sites; even with renamed/hidden folders, burst them all up, to see how secure you are not.
        • 12603
        • 13 Posts
        Quote from: donshakespeare at Mar 12, 2013, 08:14 AM
        Are you looking for something like this? Try and see what happens
        $redirect_url = $modx->makeUrl(337); //337 is id of destination page where you want unwanted folk directed to
        $present_url = $_SERVER['HTTP_REFERER']; //where user is coming from
        $site_url = $modx->config['site_url']; //your site's full url
        $worldpay_url = "".$site_url."worldpay.html"; //url of worldpay to be matched
        
        if ($present_url !== $worldpay_url) // if referring url does not match worldpay.html...
        {
        $modx->sendRedirect($redirect_url); // ...please get lost, go to page 337
        die();
        }
        Create this snippet, check_url and call it in download.html, [[!check_url]]. Alter the url names inside...
        Note, although the common user would suffer this redirection mandate, an advanced user can fake his or her referring url.

        Brilliant.
          • 8822
          • 203 Posts
          Hi, thanks! That is what i am looking for - i am aware that this will not stop an advanced user faking a URL, but will suffice for a 'quick fix'.

          With the code you gave above, does the referring URL have to be an exact match and not just anything from 'worldpay.com'?

          The exact URL from worldpay will differ every time a new transaction is handled, so although https://secure-test.worldpay.com will remain the same, what comes after that will differ..... what should i put for 'worldpay.html'?

          $site_url = $modx->config['www.myurl.com']; //your site's full url
          $worldpay_url = "".$site_url.".worldpay.com"; //url of worldpay to be matched
          


          Thanks for your help


            • 42562
            • 1,145 Posts
            Quote from: Emily
            $site_url = $modx->config['www.myurl.com']; //your site's full url
            $worldpay_url = "".$site_url.".worldpay.com"; //url of worldpay to be matched
            In the original snippet, please do not change anything except line 4, worldpay.html ....everything else must be intact.

            Yes, the referring URL has to be an exact match, that's how I understood your first post.

            For your latest question, try this
            <?php
            $redirect_url = $modx->makeUrl(337); 
            $present_url = $_SERVER['HTTP_REFERER']; //user's referring URL
            //now looking for https://secure-test.worldpay.com, if it is not found, user is kicked out.
            if (strpos($present_url,'https://secure-test.worldpay.com') === false) { 
            $modx->sendRedirect($redirect_url);
            die();
               }
            ?>
            Do alter ONLY line 5: put the exact thing you want in there. Have any problems with this snippet...?


              TinymceWrapper: Complete back/frontend content solution.
              Harden your MODX site by passwording your three main folders: core, manager, connectors and renaming your assets (thank me later!)
              5 ways to sniff / hack your own sites; even with renamed/hidden folders, burst them all up, to see how secure you are not.
              • 8822
              • 203 Posts
              Thanks!

              It redirects perfectly if the URL is not worldpay, but still doesn't display the correct page if redirected from worldpay. How do i find out what the system thinks HTTP_REFERER is to determine whether this is the problem?
                • 8822
                • 203 Posts
                it appears that HTTP_REFERER is not being set by worldpay and comes through to my website as blank, hence the fact that the page is not being displayed. Do some websites do this or am i missing something?
                  • 42562
                  • 1,145 Posts
                  but still doesn't display the correct page if redirected from worldpay.
                  Let us disable a few things. This code should spit out the exact URL of the page you are coming from; then from there you can see what's going on, and make changes accordingly.
                  <?php
                  //$redirect_url = $modx->makeUrl(337); 
                  $present_url = $_SERVER['HTTP_REFERER'];
                  //if (strpos($present_url,'https://secure-test.worldpay.com') === false) { 
                  //$modx->sendRedirect($redirect_url);
                  //die();
                  // }
                  echo $present_url; //will display url of the worldpay referring page
                  
                    TinymceWrapper: Complete back/frontend content solution.
                    Harden your MODX site by passwording your three main folders: core, manager, connectors and renaming your assets (thank me later!)
                    5 ways to sniff / hack your own sites; even with renamed/hidden folders, burst them all up, to see how secure you are not.
                    • 42562
                    • 1,145 Posts
                    Problem is probably because this deal is between SSL page and non-SSL (downloads.html). The referrer header is not coming through or sent by the web browser... Your worldpay is https(ecure) right?
                      TinymceWrapper: Complete back/frontend content solution.
                      Harden your MODX site by passwording your three main folders: core, manager, connectors and renaming your assets (thank me later!)
                      5 ways to sniff / hack your own sites; even with renamed/hidden folders, burst them all up, to see how secure you are not.
                      • 8822
                      • 203 Posts
                      yes that's right, it https. Nothing i can do about the lack of HTTP_REFERER i guess?