We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 130
    • 17 Posts
    This is a splinter question from this thread:
    https://forums.modx.com/thread/89452/loading-a-swf-via-a-static-resource#dis-post-492033

    I need to allow or deny access to a folder on the server based on whether someone's logged in to modx. I know the normal way is to use a static resource, but I can't do that because I'm trying to load a swf file that is linking to other files in a protected folder. Is this possible?

    This could be an inexpensive/low tier way to display content that you don't want to be downloaded/copied/pasted.
      • 130
      • 17 Posts
      Just spitballing here, (I'm not trying to answer my own question, but adding to it as I think)

      Could session_cookie_path be combined with something in the htaccess like RewriteCond %{HTTP_COOKIE}? Like having the htaccess verify a cookie exists in a certain directory?
        • 18270
        • 68 Posts
        Interesting idea. Keep in mind that you can manually set cookies with a browser if you know what value to hack in there. But it appears that it may be possible.

        http://stackoverflow.com/questions/19382160/htaccess-compare-cookie-value-and-redirect-if-evaluation-returns-true-false

        has an interesting htaccess example of doing something like this with modrewrite. Not 100% sure if you can somehow mix this type of thing with a deny rule.

        Interested to know how you get on. It might be a way to secure those files down a bit better.
          • 130
          • 17 Posts
          Yeah, I realize cookies can be faked, though they'd have to login to know which cookie it is they need to fake. And they still need to login access the page that loads the swf. A deny rule wouldn't work in my case (which was really my whole problem) because of the way the flash file was calling images.

          The modwrite actually worked just fine, I created a snippet which creates a cookie on the login redirect page. Then I used this htaccess file

          RewriteEngine on
          RewriteCond %{HTTP_COOKIE} !cookiename
          RewriteRule ^(.*)$ http://yourwebsite/403/$1 [r=301,nc]

          So [for the htaccess challenged that may stumble on this] what's happening here is that if the cookie isn't found, it's rewriting the request to the sites 403 page.

          Again, is this the most locked down way ever in history? No, but it's not too bad.
            • 130
            • 17 Posts
            BTW, this was just my solution, if anyone else has a better suggestion, please feel free!