We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 22827
    • 129 Posts
    There are a number of ways to set up private access to content at a user (rather than group) level, however our customer also wants to be able to also store documents. The user would come to their site, go through a login process, then see a list of downloadable documents that are for them alone.

    These documents would mostly be PDFs and should not be visible or accessible by other visitors. As the backing of MODX is a webserver, it wouldn't be possible for MODX to prevent access to PDFs in the filestore if someone was able to guess the name (and access directly).

    So the filestore itself needs to be secured. I am thinking a document management system of some kind would be best, with integration with MODX for authentication.

    Has anyone else done something similar, or perhaps there is a way that I can do this with MODX natively?
      • 3749
      • 24,544 Posts
      Take a look at this: http://rtfm.modx.com/extras/revo/filedownload-r

      You could do that on a page and protect the page like this: http://bobsguides.com/blog.html/2013/05/22/protecting-pages-the-easy-way/
        Did I help you? Buy me a beer
        Get my Book: MODX:The Official Guide
        MODX info for everyone: http://bobsguides.com/modx.html
        My MODX Extras
        Bob's Guides is now hosted at A2 MODX Hosting
        • 28042 ☆ A M B ☆
        • 24,524 Posts
        Static resources are a good way to do this. You could even use MIGXdb to manage the static resources. While (at this time) Static Resources do not completely work with Media Sources, you can use a Media Source pointing to a directory outside of the web root to store the actual files that the Static Resources are serving. The visitor never sees the path to the file, he only sees the URL for the Static Resource.

        To do this, I create a custom Resource Type of PDF (or whatever), specifying the mime type and binary as appropriate. The Content Disposition of the PDF resources will be "attachment", allowing the link to the Static Resource to behave like any link to a downloadable file - the actual behavior will depend on the browser's configuration whether a PDF reader plugin is triggered or a download dialog pops up. Internally, MODx sets different headers and streams the file in the case of a binary Static Resource.

        Then I create a Media Source with its path being the full server path to the directory where the .pdf files reside, and the "relative" options set to No.
        /full/path/to/files/


        When creating a new Static Resource, I am able to access the basic File Manager, selecting my Media Source. I can upload and select files as usual. Since the Static Resource only stores the file's path inside of the Media Source, I use a chunk containing the Media Source's defined path, like this:
        [[$pathPrefix]]rest/of/path/to/file.pdf

        A plugin could be used to add the chunk tags to the Static Resource's content automatically, or the user can add it himself.

        When being served, MODx will process the chunk so its content gets added to the rest of the path, like processing a chunk in any other resource's content. This way if the files get moved, and the Media Source gets changed, you can simply edit the chunk to modify the Static Resource's full path.
        /full/path/to/files/rest/of/path/to/file.pdf


        Another easier but more restrictive method is to also have the same path in the Media Source's URL (ignored above, since a URL has no meaning for files outside of the web root). Then the Static Resource will pick up the entire path, but the user will need to remember to insert the leading / to the path (or, again, a plugin using onBeforeDocFormSave could do this automatically). The problem is that now the full path is stored in the database as the content for every static resource, so if you move the files and edit the Media Source, all existing Static Resources will still have the original full path.

        Eventually I (and others) intend to have Static Resources deal with Media Sources, just as Static Elements and TVs do, so that files stored on external file storage services can be accessed with a Media Source.
          Studying MODX in the desert - http://sottwell.com
          Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
          Join the Slack Community - http://modx.org
          • 22827
          • 129 Posts
          Great, thanks guys, I'll explore these. It certainly seems like this is something I can manage securely within modx.

          Particularly thanks for the extra mile(s) effort there Susan.