We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 40088
    • 708 Posts
    Revo 2.3.3
    NewsPublisher 2.0.2

    I'm fairly certain the answer to the following will be a resounding “No” or “Not without Matrix-level programming skills”, but I want to ask so at least I can say I've done my due diligence.

    I have a members area where users can view/upload (to Amazon) a variety of media from the front-end via TinyMCE/Media Browser, however they are not allowed to delete anything. As it stands all signed-in members can view (and/or use) any media that's been uploaded by other members. Technically everything works ok.

    However, some members have requested more control over their own uploaded media, meaning they don't want their files to be viewable or usable by other members (front-end), plus they want to be able to delete their own stuff. Already I can see the technical hurdles piling up.

    Now for the $64 question:
    When a new member signs-up is there a way to automatically create a unique ‘media’ folder for each user where they can upload and delete their own files from within their front-end account? Of course this folder would also need to somehow dynamically tie-in with the RTE in NP on a member-by-member basis (my head is already spinning).

    Actually, even without the RTE integration if there was a way to give the member a very limited ability to manage their own media that would be a step in the right direction. I'm open to alternative ideas.

    This question has been answered by donshakespeare. See the first response.

    [ed. note: todd.b last edited this post 11 years, 7 months ago.]
      Todd
      • 4172
      • 5,888 Posts
      This should be possible with a dynamic mediasource.
      MIGX has a snippet included, where you can create userspecific dynamic mediasources.
      With this they are autocreated and they have only access to their own file-directory.
      Put that snippet into the path and url - fields of the mediasource.
      Add a .htaccess - file with 'deny from all' to the main-directory of the user-folders or put that directory outside of the web-root.

      Not sure how this would work with NP and the tinyMCE/filebrowser - combi, but I think there should be ways to get that working.
        -------------------------------

        you can buy me a beer, if you like MIGX

        http://webcmsolutions.de/migx.html

        Thanks!
      • discuss.answer
        • 42562
        • 1,145 Posts
        Here is an alternate idea for you, the $0 solution!
        Tutorial http://www.leofec.com/modx-revolution/using-responsive-filemanager-in-modx.html

        Using the absolutely fantastic Responsive FileManager instead of the MODx in-built one...
        The upload destination is the server on which MODx is on, although the author responded to this question:
        Any chance of Amazon S3 support in the near future?
        You can take a lok at the AS3 API, it is not to heavy to create such a feature by Yourself. There are verry good tutorials and descriptions to find. I wish You good luck, have fun!
        It ties seamlessly into TinyMCE, NewsPublisher, front-end galore etc; users never have to access mgr context or files in any shape or form.
        This add-on also stands alone with its direct url, so it is not restricted to TinyMCE or whatnot.

        And of course, a user folder is created, not on sign-up, but when the user accesses this Responsive FileManager, according to the permission you give them.

        ...meaning they don't want their files to be viewable or usable by other members (front-end), plus they want to be able to delete their own stuff
        Only owners can edit/delete own stuff. As for viewing, good luck, if it's on the internet it is public.
        You may learn how to use .htaccess + php + MODx to determine what user is which and whom to deny viewing access.
        http://www.thebigblob.com/how-to-restrict-user-access-to-content-in-folders-using-php-and-apache-htaccess-files/
          TinymceWrapper: Complete back/frontend content solution.
          Harden your MODX site by passwording your three main folders: core, manager, connectors and renaming your assets (thank me later!)
          5 ways to sniff / hack your own sites; even with renamed/hidden folders, burst them all up, to see how secure you are not.
          • 40088
          • 708 Posts
          @Bruno17 Thank you. This sounds interesting.

          @donshakespeare That tutorial seems to be missing a few key points but I followed it as best I could and although the plugin launches in Tiny (front- and back-end) the dialog window loads the site homepage, not a file browser. Any ideas? [ed. note: todd.b last edited this post 11 years, 7 months ago.]
            Todd
            • 42562
            • 1,145 Posts
            The tutorial is quite complete.
            The tut, simply shows you how to integrate with MODx.

            the dialog window loads the site homepage, not a file browser
            Note: MODx backend TinyMCE is hopelessly outdated (last time I checked) and won't work with this add-on.
            Does it work in the front-end at least?

            Did you test the add-on without MODx (and my modification), to see if and how it works?
            If my code crashed the process, then that's a whole different species of trouble.
              TinymceWrapper: Complete back/frontend content solution.
              Harden your MODX site by passwording your three main folders: core, manager, connectors and renaming your assets (thank me later!)
              5 ways to sniff / hack your own sites; even with renamed/hidden folders, burst them all up, to see how secure you are not.
              • 40088
              • 708 Posts
              Both the front- and back-end dialog windows show the homepage.

              Could it be the File System media source setting?
                Todd
                • 40088
                • 708 Posts
                @Bruno17
                I followed the MIGX docs for creating a dynamic mediasource but when I try uploading a file I get this:

                "The specified directory is not a directory."

                The directory exists and is writable, I tried both 755 and 777.
                  Todd
                  • 42562
                  • 1,145 Posts
                  The only reference to homepage is from line 18 of /assets/filemanager/config/config.php
                  //only trusted members of the Club have access to filemanger - better security
                  if ($modx->user->isMember('Writers-Club') ) {
                   } else {
                  header( 'Location: http://www.homepage.com' ) ; //send unwanted people home
                  }

                  Make sure you customized the code according to your needs. For debugging purposes, remove this piece of code.

                  Does the dialog window have a title of filemanager etc etc?
                    TinymceWrapper: Complete back/frontend content solution.
                    Harden your MODX site by passwording your three main folders: core, manager, connectors and renaming your assets (thank me later!)
                    5 ways to sniff / hack your own sites; even with renamed/hidden folders, burst them all up, to see how secure you are not.
                    • 40088
                    • 708 Posts
                    The dialog title is: RESPONSIVE:: Filemanager. [ed. note: todd.b last edited this post 11 years, 7 months ago.]
                      Todd
                      • 42562
                      • 1,145 Posts
                      Sorry, I can't tell what you are doing wrong.
                        TinymceWrapper: Complete back/frontend content solution.
                        Harden your MODX site by passwording your three main folders: core, manager, connectors and renaming your assets (thank me later!)
                        5 ways to sniff / hack your own sites; even with renamed/hidden folders, burst them all up, to see how secure you are not.