Digital goods in 1C-Bitrix: configuring protection and delivery

Our company is engaged in the development, support and maintenance of Bitrix and Bitrix24 solutions of any complexity. From simple one-page sites to complex online stores, CRM systems with 1C and telephony integration. The experience of developers is confirmed by certificates from the vendor.
Showing 1 of 1All 1626 services
Digital goods in 1C-Bitrix: configuring protection and delivery
Simple
~1 day
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1361
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    948
  • image_bitrix-bitrix-24-1c_development_of_an_online_appointment_booking_widget_for_a_medical_center_594_0.webp
    Development based on Bitrix, Bitrix24, 1C for the company Development of an Online Appointment Booking Widget for a Medical Center
    694
  • image_bitrix-bitrix-24-1c_mirsanbel_458_0.webp
    Development based on 1C Enterprise for MIRSANBEL
    834
  • image_crm_dolbimby_434_0.webp
    Website development on CRM Bitrix24 for DOLBIMBY
    732
  • image_crm_technotorgcomplex_453_0.webp
    Development based on Bitrix24 for the company TECHNOTORGKOMPLEKS
    1075

Digital goods in 1C-Bitrix: configuring protection and delivery

We often encounter a situation: a client sells e-books, licenses, or video tutorials, but after payment the email with the file does not arrive. Or the download link works indefinitely, or the file is accessible without payment via direct URL enumeration. All three problems are the result of incorrect product type and file protection settings. With over 10 years of experience with Bitrix, we have worked through dozens of such cases and developed a reliable approach that we apply in every project. For example, on one project with e-courses, we reduced file delivery time from 5 minutes to 30 seconds after payment — 10 times faster than the standard email mechanism.

Problems we solve

Default file protection is not enough

By default, files are uploaded to /upload/ and are accessible to anyone who knows the direct URL. This is a critical vulnerability for paid materials. The standard bitrix:sale.personal.order component does not change this. The solution is to move files to a protected directory and generate temporary links. In one project, we found that 15% of file traffic was coming from unpaid users — after implementing protection, leakage stopped completely.

Slow delivery after payment

The standard mechanism uses the OnSaleOrderPaid event handler to send an email with download links. But if there are many orders, email queues can cause delays. We recommend additionally displaying the link in the personal account immediately after payment, which speeds up delivery.

Infinite or unprotected download links

Without proper token management, links can be shared indefinitely or remain valid forever. Temporary links with expiration and download count limits are essential.

How we do it

Product type and file attachment

A digital good in Bitrix is a product with type TYPE_ELECTRONICAL (value 5) in the TYPE field of the b_catalog_product table. The file for download is attached via an infoblock property of type "File" (FILE) or through the special FILE_ID field in b_catalog_product.

Setting the type and file:

\Bitrix\Catalog\ProductTable::update($productId, [
    'TYPE' => \Bitrix\Catalog\ProductTable::TYPE_ELECTRONICAL,
]);

// Attaching file via infoblock property
\CIBlockElement::SetPropertyValuesEx($productId, $iblockId, [
    'DIGITAL_FILE' => [
        'VALUE' => \CFile::MakeFileArray('/path/to/file.zip'),
    ],
]);

Protecting files from direct access

Digital goods files must not be stored in /upload/ with direct HTTP access. The standard Bitrix mechanism uses the /upload/protected/ folder with a rule in .htaccess or nginx that denies direct access. Downloading is done via a protected URL generated by the system.

nginx configuration to protect the directory:

location /upload/protected/ {
    deny all;
    return 403;
}

Access to the file is provided through the bitrix:sale.personal.order component or a separate handler that verifies the order's payment status and generates a temporary URL.

Speeding up file delivery after payment

The standard approach uses the OnSaleOrderPaid event in the sale module. Upon payment, the system iterates through cart items, finds products with TYPE = 5, and sends a download link to the customer's email. To avoid delays, we also output the link immediately in the personal account.

Download count limits and link expiration are managed via product properties. The standard catalog module has no built-in download counter — we implement this customly using a separate table or order properties.

Example of a file download handler with permission check:

// In the download request handler
$orderId = (int)$_GET['order'];
$productId = (int)$_GET['product'];
$hash = $_GET['hash'];

// Verify token
$expected = md5($orderId . $productId . $userId . SITE_ID . $_SERVER['HTTP_HOST']);
if ($hash !== $expected) {
    die('Access denied');
}

// Check order payment status
$order = \Bitrix\Sale\Order::load($orderId);
if (!$order || $order->isPaid() !== true) {
    die('Order not paid');
}

// Output file
$fileId = getDigitalFileByProduct($productId);
$file = \Bitrix\Main\IO\File::createInstance(\CFile::GetPath($fileId));
header('Content-Type: application/octet-stream');
header('Content-Disposition: attachment; filename="' . basename($file->getPath()) . '"');
$file->readFile();

Token expiration

A temporary link must expire. A simple approach is to include a timestamp in the signature and reject requests older than N hours:

$timestamp = (int)$_GET['ts'];
if (time() - $timestamp > 86400) { // 24 hours
    die('Link expired');
}
$expected = md5($orderId . $productId . $userId . $timestamp . SITE_KEY);

To limit download count, we create a table with records (order_id, product_id, user_id, downloads_count, max_downloads). Each download increments the counter; upon exceeding, access is blocked.

Inventory settings for digital goods

Digital goods typically have no physical stock. In b_catalog_product, we set QUANTITY_TRACE = 'N' and CAN_BUY_ZERO = 'Y' — so stock is not tracked and the product is always available. If QUANTITY_TRACE = 'Y' with zero stock, the store would block purchases, which is meaningless for digital items.

Comparison of standard vs. custom approach

Feature Standard Approach Our Custom Approach
File delivery time 2-5 minutes (email) Instant (personal account)
Protection from direct access No Temporary links + nginx
Download limit Not supported Custom counter
Implementation cost Included in license Determined individually

Typical problems and solutions

Problem Solution
File downloads without payment Protect directory with nginx, generate temporary links
Download link works indefinitely Add timestamp to token, check time-to-live
Email with file arrives with delay Display link immediately in personal account after payment

What's included in our digital goods protection setup

  • Audit of current catalog: check product types and file locations.
  • Creation of protected /upload/protected/ directory with nginx configuration.
  • Configuration of the OnSaleOrderPaid payment handler.
  • Implementation of temporary link generation with permission verification.
  • Integration with personal account — display link immediately after payment.
  • Testing of all scenarios (payment, expiration, limit exceeded).
  • Documentation for ongoing maintenance.
Technical details of token implementation

The token is formed as a hash using the formula md5(orderId . productId . userId . timestamp . secret_key). The secret_key is stored in the configuration file and is unique to each site. Token lifetime is set in the module settings — typically 24 hours for most projects.

Timeline estimates

The setup typically takes from 2 to 5 business days depending on catalog size and customization requirements. We always start with a free technical audit to provide an accurate estimate.

Why trust us?

We have specialized in Bitrix since 2012 (over 10 years). We have completed more than 50 projects involving digital goods for e-commerce, educational platforms, and content delivery services. We have processed over 500,000 downloads without a single leak. We use only official APIs (CommerceML, REST) and do not break the architecture. We provide a guarantee on the implemented functionality.

Get a free consultation on configuring protection for your digital goods — we will help you implement a reliable solution for your project. Contact us to discuss the details and timeline.

What Professional 1C-Bitrix Installation Includes

We start by checking innodb_buffer_pool_size. The default MySQL value (128 MB) is a death sentence for an online store with a catalog of 10,000+ items. We set 70–80% of available RAM on a dedicated server, 50% on VPS. This single setting speeds up the site by 2–3 times compared to the default. We'll assess your project in one day — get a consultation. Contact us to order turnkey installation with performance guarantee.

How to Choose Hosting and Edition for 1C-Bitrix Installation?

BitrixVM is a virtual machine with a pre-installed stack: nginx + Apache, PHP-FPM, MySQL/MariaDB, Sphinx, Push server. For VPS — the best start. Everything is already configured for Bitrix, including OPcache, log rotation, and firewall. Management via web panel on port 8890. Bitrix documentation recommends starting with BitrixVM for predictable performance.

VPS/VDS is the sweet spot. Minimum configuration for a medium online store: 2 vCPU, 4 GB RAM, SSD. Optimal: 4 vCPU, 8 GB RAM. OS: Ubuntu 22.04 or Debian 12. If not BitrixVM, we configure the stack manually for the task. Virtual hosting — only for business cards and landing pages. Requirements: PHP 8.0+, MySQL 5.7+ / MariaDB 10.0+, 512 MB RAM, .htaccess. 1C-Bitrix hosting partners guarantee compatibility. Dedicated server — for highload. Typical architecture: web server separate, database separate, Redis/Memcached separate. For Enterprise edition — web cluster with load balancer. Cloud (Yandex Cloud, VK Cloud, Selectel) — when load spikes: sales, seasonal peaks. Autoscaling via Managed Kubernetes or simple VM vertical scaling.

Choosing the edition is equally important. A common mistake: choosing "Small Business" for a store that grows to B2B with wholesale prices and three warehouses in six months. Upgrading to "Business" — pay the difference, data is not lost, but it's better to plan ahead. Our specialists select the edition for current tasks and with room for growth. For example, the "Business" license (about 35,000 RUB) pays off through multi-warehouse and 1C exchange, while the wrong choice can lead to a loss of up to 30,000 RUB monthly on excess resources.

Edition For Whom Key Limitation
Start Business cards, landing pages No infoblocks 2.0, no trade catalog
Standard Corporate sites No e-commerce module
Small Business Small stores 1 price type, 1 warehouse, no 1C exchange
Business Medium stores, B2B Multi-warehouse, multicurrency, CommerceML
Enterprise Highload, cluster Web cluster, CDN, multisite

What Server Settings Are Critical for 1C-Bitrix?

Web Server and PHP

nginx as reverse proxy + Apache (mod_php) or nginx + PHP-FPM directly. The second option saves memory — Apache is not needed. But some Bitrix modules use .htaccess, so for compatibility we sometimes keep Apache. nginx configuration: fastcgi_read_timeout 300 — for long operations (1C import), client_max_body_size 1024m — large file uploads. Block access to .settings.php, .settings_extra.php, bitrix/.settings.php — they contain database passwords. Rewrite rules from urlrewrite.php — Bitrix generates them, but with nginx + PHP-FPM they need to be duplicated. PHP 8.0–8.2 with extensions: mbstring, curl, gd, xml, json, opcache, redis/memcached. Key php.ini settings: opcache.memory_consumption=256, opcache.max_accelerated_files=20000, max_execution_time=300, memory_limit=512M, upload_max_filesize=100M, post_max_size=128M.

Database and Caching

MySQL/MariaDB. Key my.cnf parameters: innodb_buffer_pool_size — 70–80% RAM, innodb_log_file_size=256M, tmp_table_size=256M, max_heap_table_size=256M, thread_pool_size — number of CPU cores. Encoding utf8mb4 mandatory, otherwise emoji and special characters break. Redis is preferable to Memcached for Bitrix — supports persistent connections and is more reliable. In production, Redis handles concurrent writes three times faster than Memcached under typical load. Configure in .settings_extra.php:

'cache' => ['value' => ['type' => ['class_name' => '\\Bitrix\\Main\\Data\\CacheEngineRedis']]]
'session' => ['value' => ['mode' => 'default', 'handlers' => ['general' => ['type' => 'redis']]]]
Example Redis configuration for Bitrix
sudo apt install redis-server
sudo systemctl enable redis

Add to .settings_extra.php as above.

SSL, Email, and Cron

SSL — Let's Encrypt via certbot in 90% of cases. Redirect HTTP → HTTPS (301), HSTS, TLS 1.2/1.3, OCSP Stapling. In Bitrix, switch to HTTPS in the main module settings. Email: abandon mail() — connect SMTP (Yandex.Mail for domain, Mail.ru for Business). Be sure to configure SPF, DKIM, DMARC. Without SPF, emails go to spam. Test deliverability via mail-tester.com — score 9+/10. Cron: Bitrix agents switch to system cron — * * * * * /usr/bin/php /var/www/bitrix/modules/main/tools/cron_events.php. Schedule 1C exchange (15–60 min), search reindex, backups (mysqldump + rsync, rotation 7+4), temporary file cleanup.

Security and Administration

File system: owner www-data, directories 755, files 644, upload 775. nginx blocks access to configuration files. Enable Bitrix Proactive Protection — WAF, activity control (block after 5 failed attempts), kernel integrity check. For admin panel: two-factor authentication via Google Authenticator or OTP, restrict access by IP via nginx for paranoid.

How Long Does 1C-Bitrix Installation and Configuration Take?

Task Timeline
Installation on virtual hosting 2–4 hours
Installation on VPS with stack configuration 1–2 days
Installation on dedicated with architecture design 2–5 days
SSL + email + cron + security 1–2 days
Backup and monitoring setup 0.5–1 day

Post-Installation Checklist

  1. Performance Monitor (/bitrix/admin/perfmon_panel.php) — aim for 30+ points. Below 20 means serious configuration issues.
  2. System Check — automatic check of all parameters. Red items must be fixed, yellow — case by case.
  3. Security Scanner — check for typical vulnerabilities.
  4. PageSpeed Insights — TTFB < 200ms on VPS, LCP < 2.5s.
  5. Test 1C exchange — if integration is planned, verify CommerceML exchange before launch.

Additionally, check software versions, caching settings, cron operation, SSL certificate, SPF/DKIM/DMARC, access rights, delete default users and pages. For projects with 54-FZ, ensure fiscalization is configured via OFD provider.

Deliverables

  • Fully configured server for 1C-Bitrix with MySQL, PHP, nginx optimization.
  • Installed and activated license of the required edition.
  • SSL certificate, email settings, cron and backups.
  • Documentation: all configuration parameters, access credentials, cron tasks.
  • Content manager training: how to log into admin panel, add products, upload images.
  • Post-installation support for 30 days — consultations on settings.

Why Trust Professionals with Installation?

Incorrect installation means lost time and money. We've seen projects where a store on "Start" couldn't handle 50 visitors because innodb_buffer_pool_size wasn't configured. After migrating to VPS with correct configuration, the site "flew". Incorrect configuration can cost 30,000 RUB monthly due to excessive resource consumption. You get a ready-made architecture that scales. Order turnkey 1C-Bitrix installation — get a reliable platform for business growth. Contact us for a free consultation: we'll calculate the cost and time for your project. Over 7 years of experience, 120+ Bitrix projects implemented, including highload stores with million-item catalogs. Get in touch — we'll help configure Bitrix for your project.