Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Views Bootstrap 5.5.4 — Minor update available for module views_bootstrap (5.5.4). Release: Rightup theme 1.0.3 — Minor update available for theme vartheme_bs5_rightup (1.0.3). Release: CommentOn 1.0.6 — Minor update available for module commenton (1.0.6). Release: ChatGPT Ads 1.0.3 — Minor update available for module chatgpt_ads (1.0.3). Release: Opensolr Search 5.1.3 — Minor update available for module opensolr_search (5.1.3). Release: ServiceM8 Webform Integration 1.2.1 — Minor update available for module servicem8_webform (1.2.1). Release: PostfixAdmin 1.0.0 — Initial release available for module postfix_admin (1.0.0)! Release: ip_analyser 1.0.3 — Minor update available for module ip_analyser (1.0.3). Module Revived: Swagger-PHP OpenAPI 3 documentation generator 1.0.0 — Module swagger_php updated after 10 months of inactivity (1.0.0). Security Coverage: Microsoft Azure AI — Module ai_provider_azure now has official Drupal security advisory coverage.

Webform Attachment Gated Download

Security covered

Part of the Webform ecosystem · 161 projects

View on drupal.org

The purpose of this module is to ask visitors to fill out a webform before being allowed to receive a file. The file will be sent as an attachment by email, if it is configured as shown below.

This module provides a field formatter for file, image, and media types which links to a webform.

The module also provides a "Attachment File (Gated Download)" webform element which must be used for the module to work.

Instructions for Use

  • Make sure $settings['hash_salt'] has a value in settings.php
  • Create a webform
  • Add an "Attachment File (Gated Download)" webform element to the webform
  • Setup the webform email handler to include attachments
  • Setup a file, image, or media field - can be private or public
  • Set the display type for the field to "Webform Gated Download Link"
  • Choose the button text and webform from the formatter options
  • That's it :-)

Generate your own link

It's possible to generate your own link from code:

  • Call \Drupal\webform_attachment_gated_download\QueryParser::getQueryValueFromFid()
  • Use the return value with a URL query key of 'gated_fid'.

Security Considerations

The file ID in the URL parameter is protected by a hash, which is why you must provide a $settings['hash_salt'] value. This way the URL cannot be manipulated to attach other files to the webform submission.

Anybody who fills out your form will receive an attachment, regardless if the file is public or private and regardless of whether they are logged in or not, and ignoring all other permissions in place. THIS IS BY DESIGN and allows you to protect private files behind a gated webform.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Mar 2024
Latest release
2 years ago
Releases (12 mo)
0
Maintenance
Dormant

Releases

Version Type Core Release date
8.x-1.5 Stable Mar 9, 2024