3 ms·
The service could send a special "auth" key along as parameter when forwarding. E.g.: http://example.com/secret.php?key=dh498 http://example.com/secret.php?key=
by phoboslab 16y ago
The service could send a special "auth" key along as parameter when forwarding. E.g.: http://example.com/secret.php?key=dh498 http://example.com/secret.php?key=dh498
In secret.php on your server you could then ask the Gumroad API (via another http request) how often this key was already used and deny or allow access. This would be super easy to implement for the seller - just paste in ~5 lines of PHP code.
- mikaelgramont 16y agoYou could allow access to that link about 5 times. After that, display a link that says something along the lines of "Thanks for using us. This link has been used 5 times already. If you wish to access it again, click here and we will send you an email with another authorization code (or whatever)". That way your users don't lose access to their stuff, and you can keep track of abuse. It's not a perfect solution, but it's better than nothing.
- tadruj 16y agoOnce you give out a destination link, it's out. Even if it's a redirect with a nice gumroad URL. Gumroad has no control over it. If Gumroad would be caching a file, this could be done using credit card security code re-entry every 5 attempts to DL or such.