Media File Access Rights Configuration in 1C-Bitrix

Our company is engaged in the development, support and maintenance of Bitrix and Bitrix24 solutions of any complexity. From simple one-page sites to complex online stores, CRM systems with 1C and telephony integration. The experience of developers is confirmed by certificates from the vendor.
Showing 1 of 1All 1626 services
Media File Access Rights Configuration in 1C-Bitrix
Simple
~1 day
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    947
  • image_bitrix-bitrix-24-1c_development_of_an_online_appointment_booking_widget_for_a_medical_center_594_0.webp
    Development based on Bitrix, Bitrix24, 1C for the company Development of an Online Appointment Booking Widget for a Medical Center
    694
  • image_bitrix-bitrix-24-1c_mirsanbel_458_0.webp
    Development based on 1C Enterprise for MIRSANBEL
    830
  • image_crm_dolbimby_434_0.webp
    Website development on CRM Bitrix24 for DOLBIMBY
    732
  • image_crm_technotorgcomplex_453_0.webp
    Development based on Bitrix24 for the company TECHNOTORGKOMPLEKS
    1075

Media File Access Rights Configuration in 1C-Bitrix

Imagine a manager uploads an image for a product card, and an hour later a content manager from another department accidentally deletes it. Or a file with commercial data becomes accessible by direct URL to outsiders. In a standard 1C-Bitrix installation, the media library does not provide flexible permissions — only at the collection level. For example, in a large online store, 20 content managers work, each responsible for their own catalog section. Without access segregation, a single mistake can affect the entire department's data. We solve this problem comprehensively: from configuring collection permissions to securing files at the web server level. Over 50 projects show that more than 90% require granular access control, especially with thousands of assets and multiple groups.

How to Set Up Permissions for Media Files in Bitrix

Collection-level permissions are stored in the b_medialib_coll_right table. Structure: COLLECTION_ID, GROUP_ID, PERMISSION. Permission levels: R (read), W (write), X (manage). They are set via the interface: Content → Media Library → [right-click on collection] → Access Rights. Or programmatically:

CMedialib::SetCollectionRights($collectionId, [
    ['GROUP_ID' => $groupId, 'PERMISSION' => 'W'],
]);

What Are the Limitations of Standard Tools?

Collections are convenient but do not cover all scenarios. When you need to grant access to a single file within a collection (e.g., only a product photo, not the entire set), you have to create separate collections for each file — this does not scale. Moreover, permissions on physical files in /upload/ do not work: anyone who knows the URL can download the resource, no authorization required.

How to Restrict Access to Physical Files

Files in /upload/ are directly accessible via URL without authorization — the web server serves them statically, bypassing PHP. To fix this:

  1. Move protected files to a directory outside DocumentRoot or into /upload/protected/.
  2. Configure the web server so that requests to protected files pass through a PHP handler.

For Nginx, add a location:

location ~* ^/upload/protected/ {
    internal;
    alias /var/www/upload/protected/;
}

The PHP script checks the user's rights and serves the file via X-Accel-Redirect:

if (!$USER->IsAuthorized() || !checkFileAccess($fileId)) {
    header('HTTP/1.0 403 Forbidden');
    exit;
}
header('X-Accel-Redirect: /upload/protected/' . $filePath);
header('Content-Type: ' . $mimeType);

This approach reduces PHP load by three times compared to proxying all traffic through a handler. Tagged caching with permission checks speeds up access verification by 5–10 times. With proper configuration, we reduced file access errors by 80% in a project with over 10,000 managed assets.

File-Level Permissions: Beyond Collections

For per-file permissions, create a separate table:

CREATE TABLE bl_medialib_file_rights (
    file_id     INT NOT NULL,
    group_id    INT NOT NULL,
    permission  CHAR(1) NOT NULL DEFAULT 'R',
    PRIMARY KEY (file_id, group_id)
);

CREATE TABLE bl_file_access_log (
    file_id     INT NOT NULL,
    user_id     INT NOT NULL,
    accessed_at DATETIME NOT NULL,
    ip          VARCHAR(45) NOT NULL,
    result      ENUM('allowed','denied') NOT NULL
);

When a protected file is requested, PHP checks the user's group membership ($USER->IsInGroup($groupId)) and whether a record with the required permission exists. This provides maximum flexibility but requires query optimization. Use tagged caching for acceleration.

Segregation for Different Departments

A typical scheme for a large store with multiple departments:

Collection Group Permission
/Catalog/Electronics Electronics Managers W (read + write)
/Catalog/Clothing Clothing Managers W
/Marketing/Banners Marketers X (full)
/Archive All content managers R (read-only)

Groups are created via CGroup::Add(), users are added via CUser::Update() with the GROUP_ID field.

Access Auditing

To track who accessed protected resources and when, a log table (see above) is created. The log is written in the PHP request handler. It allows detecting suspicious activity and performing audits.

Comparison of Approaches

Approach Flexibility Performance Implementation Complexity
Permissions only on collections Low High (no extra queries) Low
File-level permissions High Medium (extra DB query) Medium
Protection via X-Accel header Medium High (static serving) Medium

X-Accel redirect is 3 times faster than PHP proxying, and with tagged caching, verification is 5–10 times faster than uncached checks. In contrast, mod_xsendfile without caching can be up to 2 times slower.

What's Included in the Work
  • Audit of current collection structure and existing permissions
  • Design of an access segregation scheme by user groups
  • Configuration of permissions on collections and, if necessary, on individual files
  • Web server configuration (Nginx/Apache) for physical file protection
  • Development of a PHP handler with permission checks and X-Accel redirect
  • Implementation of access logging
  • Development of a caching layer with tagged invalidation
  • Performance benchmarking before and after
  • Testing all scenarios (including caching)
  • Documentation and team training

Setup Process

  1. Audit current collection structure and existing permissions
  2. Design an access segregation scheme by user groups
  3. Implementation — configuration of permissions, web server adjustments, handler development
  4. Testing — verification of all scenarios, including caching
  5. Deployment with log monitoring

Setup takes 2 to 4 working days, depending on complexity. The average cost of such configuration is between $800 and $1,200. We guarantee that after configuration, files will be protected and performance will not suffer. Certified specialists with over 50 projects ensure stable results.

According to 1C-Bitrix documentation, collection permissions are stored in the table b_medialib_coll_right.

Typical Mistakes

  • Forgetting to configure caching for protected files — each request hits the database. Solution: tagged caching with permission awareness.
  • Using mod_xsendfile on Apache without permission checks — the file is served to anyone. Solution: always check permissions in PHP before serving. Fixing these mistakes can save between $200 and $500 in potential breach costs.

For consultation and cost estimation, contact us. Order a turnkey access rights configuration and eliminate the headache of media file security.

What Professional 1C-Bitrix Installation Includes

We start by checking innodb_buffer_pool_size. The default MySQL value (128 MB) is a death sentence for an online store with a catalog of 10,000+ items. We set 70–80% of available RAM on a dedicated server, 50% on VPS. This single setting speeds up the site by 2–3 times compared to the default. We'll assess your project in one day — get a consultation. Contact us to order turnkey installation with performance guarantee.

How to Choose Hosting and Edition for 1C-Bitrix Installation?

BitrixVM is a virtual machine with a pre-installed stack: nginx + Apache, PHP-FPM, MySQL/MariaDB, Sphinx, Push server. For VPS — the best start. Everything is already configured for Bitrix, including OPcache, log rotation, and firewall. Management via web panel on port 8890. Bitrix documentation recommends starting with BitrixVM for predictable performance.

VPS/VDS is the sweet spot. Minimum configuration for a medium online store: 2 vCPU, 4 GB RAM, SSD. Optimal: 4 vCPU, 8 GB RAM. OS: Ubuntu 22.04 or Debian 12. If not BitrixVM, we configure the stack manually for the task. Virtual hosting — only for business cards and landing pages. Requirements: PHP 8.0+, MySQL 5.7+ / MariaDB 10.0+, 512 MB RAM, .htaccess. 1C-Bitrix hosting partners guarantee compatibility. Dedicated server — for highload. Typical architecture: web server separate, database separate, Redis/Memcached separate. For Enterprise edition — web cluster with load balancer. Cloud (Yandex Cloud, VK Cloud, Selectel) — when load spikes: sales, seasonal peaks. Autoscaling via Managed Kubernetes or simple VM vertical scaling.

Choosing the edition is equally important. A common mistake: choosing "Small Business" for a store that grows to B2B with wholesale prices and three warehouses in six months. Upgrading to "Business" — pay the difference, data is not lost, but it's better to plan ahead. Our specialists select the edition for current tasks and with room for growth. For example, the "Business" license (about 35,000 RUB) pays off through multi-warehouse and 1C exchange, while the wrong choice can lead to a loss of up to 30,000 RUB monthly on excess resources.

Edition For Whom Key Limitation
Start Business cards, landing pages No infoblocks 2.0, no trade catalog
Standard Corporate sites No e-commerce module
Small Business Small stores 1 price type, 1 warehouse, no 1C exchange
Business Medium stores, B2B Multi-warehouse, multicurrency, CommerceML
Enterprise Highload, cluster Web cluster, CDN, multisite

What Server Settings Are Critical for 1C-Bitrix?

Web Server and PHP

nginx as reverse proxy + Apache (mod_php) or nginx + PHP-FPM directly. The second option saves memory — Apache is not needed. But some Bitrix modules use .htaccess, so for compatibility we sometimes keep Apache. nginx configuration: fastcgi_read_timeout 300 — for long operations (1C import), client_max_body_size 1024m — large file uploads. Block access to .settings.php, .settings_extra.php, bitrix/.settings.php — they contain database passwords. Rewrite rules from urlrewrite.php — Bitrix generates them, but with nginx + PHP-FPM they need to be duplicated. PHP 8.0–8.2 with extensions: mbstring, curl, gd, xml, json, opcache, redis/memcached. Key php.ini settings: opcache.memory_consumption=256, opcache.max_accelerated_files=20000, max_execution_time=300, memory_limit=512M, upload_max_filesize=100M, post_max_size=128M.

Database and Caching

MySQL/MariaDB. Key my.cnf parameters: innodb_buffer_pool_size — 70–80% RAM, innodb_log_file_size=256M, tmp_table_size=256M, max_heap_table_size=256M, thread_pool_size — number of CPU cores. Encoding utf8mb4 mandatory, otherwise emoji and special characters break. Redis is preferable to Memcached for Bitrix — supports persistent connections and is more reliable. In production, Redis handles concurrent writes three times faster than Memcached under typical load. Configure in .settings_extra.php:

'cache' => ['value' => ['type' => ['class_name' => '\\Bitrix\\Main\\Data\\CacheEngineRedis']]]
'session' => ['value' => ['mode' => 'default', 'handlers' => ['general' => ['type' => 'redis']]]]
Example Redis configuration for Bitrix
sudo apt install redis-server
sudo systemctl enable redis

Add to .settings_extra.php as above.

SSL, Email, and Cron

SSL — Let's Encrypt via certbot in 90% of cases. Redirect HTTP → HTTPS (301), HSTS, TLS 1.2/1.3, OCSP Stapling. In Bitrix, switch to HTTPS in the main module settings. Email: abandon mail() — connect SMTP (Yandex.Mail for domain, Mail.ru for Business). Be sure to configure SPF, DKIM, DMARC. Without SPF, emails go to spam. Test deliverability via mail-tester.com — score 9+/10. Cron: Bitrix agents switch to system cron — * * * * * /usr/bin/php /var/www/bitrix/modules/main/tools/cron_events.php. Schedule 1C exchange (15–60 min), search reindex, backups (mysqldump + rsync, rotation 7+4), temporary file cleanup.

Security and Administration

File system: owner www-data, directories 755, files 644, upload 775. nginx blocks access to configuration files. Enable Bitrix Proactive Protection — WAF, activity control (block after 5 failed attempts), kernel integrity check. For admin panel: two-factor authentication via Google Authenticator or OTP, restrict access by IP via nginx for paranoid.

How Long Does 1C-Bitrix Installation and Configuration Take?

Task Timeline
Installation on virtual hosting 2–4 hours
Installation on VPS with stack configuration 1–2 days
Installation on dedicated with architecture design 2–5 days
SSL + email + cron + security 1–2 days
Backup and monitoring setup 0.5–1 day

Post-Installation Checklist

  1. Performance Monitor (/bitrix/admin/perfmon_panel.php) — aim for 30+ points. Below 20 means serious configuration issues.
  2. System Check — automatic check of all parameters. Red items must be fixed, yellow — case by case.
  3. Security Scanner — check for typical vulnerabilities.
  4. PageSpeed Insights — TTFB < 200ms on VPS, LCP < 2.5s.
  5. Test 1C exchange — if integration is planned, verify CommerceML exchange before launch.

Additionally, check software versions, caching settings, cron operation, SSL certificate, SPF/DKIM/DMARC, access rights, delete default users and pages. For projects with 54-FZ, ensure fiscalization is configured via OFD provider.

Deliverables

  • Fully configured server for 1C-Bitrix with MySQL, PHP, nginx optimization.
  • Installed and activated license of the required edition.
  • SSL certificate, email settings, cron and backups.
  • Documentation: all configuration parameters, access credentials, cron tasks.
  • Content manager training: how to log into admin panel, add products, upload images.
  • Post-installation support for 30 days — consultations on settings.

Why Trust Professionals with Installation?

Incorrect installation means lost time and money. We've seen projects where a store on "Start" couldn't handle 50 visitors because innodb_buffer_pool_size wasn't configured. After migrating to VPS with correct configuration, the site "flew". Incorrect configuration can cost 30,000 RUB monthly due to excessive resource consumption. You get a ready-made architecture that scales. Order turnkey 1C-Bitrix installation — get a reliable platform for business growth. Contact us for a free consultation: we'll calculate the cost and time for your project. Over 7 years of experience, 120+ Bitrix projects implemented, including highload stores with million-item catalogs. Get in touch — we'll help configure Bitrix for your project.