# Discourse Category Lockdown

**URL:** https://meta.discourse.org/t/discourse-category-lockdown/70649
**Category:** Plugin
**Tags:** pavilion
**Created:** [September 23, 2017, 9:26pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649 "2017-09-23T21:26:39Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![jumagura](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jumagura/32/244796_2.png) [@jumagura](https://meta.discourse.org/u/jumagura)
#### Post date: [September 23, 2017, 9:26pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/1 "2017-09-23T21:26:39Z")

</div>

This plugin allows you to restrict access to topic pages in a category. Topic titles will still show up in topic lists, search, user activity & digest emails. This is a great way to advertise the activity in a “members-only” category, which may charge for access.

It **IS NOT** designed to keep the contents of the category 100% private - if someone is determined enough they will be able to piece together the content from search results.

Each category has a couple of new settings in the Security tab:

 ![image](https://global.discourse-cdn.com/meta/original/4X/f/2/7/f274755c7139a6a9415ed10015c5d77f80fe9c93.png)

“Locked down” topics will show a (configurable) icon in the topic list if the user does not have access:

 ![10](https://global.discourse-cdn.com/meta/original/3X/c/b/cb599d643f6f3d51c34ede7244adbca9f6f17772.png)

Once clicked, unauthorised users will be redirected to a defined URL (e.g. your payment gateway). This link can be internal or external. The [static pages plugin](https://meta.discourse.org/t/static-pages-plugin-dl-static-pages/69698) works great for this.

**Plugin repository: [https://github.com/paviliondev/discourse-category-lockdown](https://github.com/paviliondev/discourse-category-lockdown)**

Thanks to @DiscourseMetrics.com for funding the development of this plugin.

Authored by @david  
Now maintained by Pavilion

---

<div class="post-metadata">

### Author: ![handythinks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/handythinks/32/119605_2.png) [@handythinks](https://meta.discourse.org/u/handythinks)
#### Post date: [April 17, 2019, 2:15am UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/9 "2019-04-17T02:15:25Z")

</div>

just checked in on this plugin (which looks exactly like what i’ve been looking for) and it looks like the build is failing. anyone using in production?

---

<div class="post-metadata">

### Author: ![X\_Code](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/x_code/32/148529_2.png) [@X\_Code](https://meta.discourse.org/u/X_Code)
#### Post date: [August 28, 2019, 8:58am UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/11 "2019-08-28T08:58:23Z")

</div>

![Screen Shot 2017-09-20 at 19.49.57.png](https://global.discourse-cdn.com/meta/original/3X/b/0/b00a8ca8dde6ef06100b4f04aaea4b7877d7906b.png)

what should be put for Groups?

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [April 12, 2020, 5:23pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/12 "2020-04-12T17:23:21Z")

</div>

Just wondering: why is this plugin in #plugin:broken-plugin ? We’re using it without any issues.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [April 13, 2020, 3:27am UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/13 "2020-04-13T03:27:10Z")

</div>

Not sure but @david probably did that for a reason back in mid-2019?

Remember 2019? 🥴

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [April 14, 2020, 2:00pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/14 "2020-04-14T14:00:26Z")

</div>

Hmm, I think I moved it because

> [@handythinks](#):
>
> looks like the build is failing

I’ll move it back to #Customization > Plugin since it sounds like it’s working 🙂

I don’t use or maintain this plugin any more, and it’s not official. If anyone would like to adopt it, let me know.

---

<div class="post-metadata">

### Author: ![fzngagan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/fzngagan/32/259349_2.png) [@fzngagan](https://meta.discourse.org/u/fzngagan)
#### Post date: [April 17, 2020, 6:20pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/15 "2020-04-17T18:20:24Z")

</div>

> [@david](#):
>
> I don’t use or maintain this plugin any more, and it’s not official. If anyone would like to adopt it, let me know.

I’m willing to adopt this, as I’m doing some work for @davidkingham on this.

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [April 20, 2020, 9:23am UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/16 "2020-04-20T09:23:51Z")

</div>

Great, thanks for taking this on @fzngagan. I’ve re-assigned the OP to you, and started the GitHub transfer.

---

<div class="post-metadata">

### Author: ![fzngagan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/fzngagan/32/259349_2.png) [@fzngagan](https://meta.discourse.org/u/fzngagan)
#### Post date: [April 20, 2020, 9:41am UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/17 "2020-04-20T09:41:51Z")

</div>

Thanks for all of that David. 🙂

---

<div class="post-metadata">

### Author: ![art.ardolino](https://avatars.discourse-cdn.com/v4/letter/a/e79b87/32.png) [@art.ardolino](https://meta.discourse.org/u/art.ardolino)
#### Post date: [April 21, 2020, 8:49pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/18 "2020-04-21T20:49:20Z")

</div>

I just installed this plugin and noticed that it allows users to create new topics in a locked down category. Can this be fixed?

---

<div class="post-metadata">

### Author: ![davidkingham](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/davidkingham/32/119528_2.png) [@davidkingham](https://meta.discourse.org/u/davidkingham)
#### Post date: [April 21, 2020, 10:26pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/19 "2020-04-21T22:26:11Z")

</div>

You need to change your category’s security settings so everyone can ‘see’ but only those in the correct group can create topics, here’s how mine is set up:

 ![image](https://global.discourse-cdn.com/meta/original/3X/6/e/6e85e268f95c6910d9ccce5d0d27e3a32facc52c.png)

---

<div class="post-metadata">

### Author: ![art.ardolino](https://avatars.discourse-cdn.com/v4/letter/a/e79b87/32.png) [@art.ardolino](https://meta.discourse.org/u/art.ardolino)
#### Post date: [April 21, 2020, 10:57pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/20 "2020-04-21T22:57:40Z")

</div>

Ah, okay, so I change “everyone” to see only and then grant my “paid member” group the full permissions. Got it. Thank you!

---

<div class="post-metadata">

### Author: ![omarfilip](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/omarfilip/32/208019_2.png) [@omarfilip](https://meta.discourse.org/u/omarfilip)
#### Post date: [June 9, 2020, 8:52pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/21 "2020-06-09T20:52:00Z")

</div>

With the [Discourse Subscriptions](https://meta.discourse.org/t/discourse-subscriptions/140818) plugin advancing in development, I’d love to see a tight integration with the Category Lockdown plugin.

Testing now with latest, a user who is not a member of the specified group can see the category and posts in it.

The plugin is active and the category security setting is this:

 ![Screen Shot 2020-06-09 at 1.39.41 PM](https://global.discourse-cdn.com/meta/original/3X/b/2/b248e59ae641e00d6a0529cff8b1e6d02f38577d.png)  
If I remove the _everyone can see_ setting, the category is no longer visible to the non-member user. So, the behavior is as if there was no Category Lockdown plugin active.

There are no errors in the log. Could it be that I’m missing another setting to get this to work?

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [June 9, 2020, 9:25pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/22 "2020-06-09T21:25:12Z")

</div>

> [@omarfilip](#):
>
> If I remove the _everyone can see_ setting, the category is no longer visible to the non-member user.

yes, that is correct, because:

> [@david](#):
>
> For this plugin to work, the category needs to be visible to the public in the ‘security’ tab

---

<div class="post-metadata">

### Author: ![Steven](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/steven/32/187890_2.png) [@Steven](https://meta.discourse.org/u/Steven)
#### Post date: [June 10, 2020, 2:57pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/24 "2020-06-10T14:57:39Z")

</div>

What are the entry restrictions for the current\_member group?

I have a forum running both plugins, it worked fine with a private group last time I checked

---

<div class="post-metadata">

### Author: ![omarfilip](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/omarfilip/32/208019_2.png) [@omarfilip](https://meta.discourse.org/u/omarfilip)
#### Post date: [June 10, 2020, 3:54pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/25 "2020-06-10T15:54:17Z")

</div>

Gah! 🤦‍♂️ I was missing the obvious and didn’t have this checked at the bottom of the category settings:

 ![Screen Shot 2020-06-10 at 8.46.24 AM](https://global.discourse-cdn.com/meta/original/3X/3/4/34ecd0780813caddb90e29a95cc8619395461c7d.png)

All is well!

---

<div class="post-metadata">

### Author: ![fzngagan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/fzngagan/32/259349_2.png) [@fzngagan](https://meta.discourse.org/u/fzngagan)
#### Post date: [June 11, 2020, 5:44am UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/26 "2020-06-11T05:44:30Z")

</div>

> [@omarfilip](#):
>
> I’d love to see a tight integration with the Category Lockdown plugin.

The subscriptions plugin should already be doing that. Its tightly integrated with discourse groups which is tightly integrated with category security settings. 😉

---

<div class="post-metadata">

### Author: ![dylanb](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/dylanb/32/139102_2.png) [@dylanb](https://meta.discourse.org/u/dylanb)
#### Post date: [June 29, 2020, 8:42pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/27 "2020-06-29T20:42:25Z")

</div>

> [@fzngagan](#):
>
> It **IS NOT** designed to keep the contents of the category 100% private - if someone is determined enough they will be able to piece together the content from search results.

I’ve been looking for a plugin that does almost exactly this (and didn’t realize it existed!). Can you clarify what this statement means though? Just that the thread will be indexed in Google?

If a user not in the group or a user who isn’t logged in navigates to the thread, they will always go to the payment gateway (or whatever link), right?

---

<div class="post-metadata">

### Author: ![fzngagan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/fzngagan/32/259349_2.png) [@fzngagan](https://meta.discourse.org/u/fzngagan)
#### Post date: [June 29, 2020, 8:44pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/28 "2020-06-29T20:44:56Z")

</div>

> [@dylanb](#):
>
> If a user not in the group or a user who isn’t logged in navigates to the thread, they will always go to the payment gateway (or whatever link), right?

Yes, but the topic entry and some bits and pieces of the content appear in the search results. If that’s ok for you, then that’s it.

Recently, I added a feature to allow category specific redirects.

If you want something more comprehensive, you can look at [Discourse Subscriptions Plugin](https://meta.discourse.org/t/discourse-subscriptions/140818)

---

<div class="post-metadata">

### Author: ![dylanb](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/dylanb/32/139102_2.png) [@dylanb](https://meta.discourse.org/u/dylanb)
#### Post date: [June 29, 2020, 8:47pm UTC](https://meta.discourse.org/t/discourse-category-lockdown/70649/29 "2020-06-29T20:47:54Z")

</div>

This seems more ideal for my use than Discourse subscriptions because I’m using WordPress and SSO for the membership. I will give it a try.

[Next page](https://meta.discourse.org/t/discourse-category-lockdown/70649.md?page=2)
