Product Attachments

Product attachments for Magento 2 (Luma and Hyvä): downloads tab, customer group and login restrictions, download counter, documents for bought products in My Account.

  • Version 1.2.2
$119

One-off payment, with 12 months of updates.

What is included

  • 12 months of new versions and fixes; the versions released in that time stay yours
  • Install with Composer, or download a zip from your account
  • Licence for one production domain, staging and development copies included
  • 30-day money-back guarantee, refund policy

No subscription or automatic renewal. Keep using the versions included in your update period. Update and licence details

Key features

  • Downloads tab on the product page (Luma) and section (Hyvä)
  • File upload or external URL, with file type icons
  • Assign in the product form, by category, by SKU or with a mass action
See all features

Composer package softaware/module-product-attachments

  • Answers before the question

    Assembly instructions, size charts and data sheets sit on the product page, where customers look for them.

  • Only the right people download

    Limit a file to signed-in customers, to customer groups or to customers who bought the product. The real file path is never shown.

  • Service after the sale

    Buyers find manuals and certificates for the products they ordered under My Account, and optionally in the order email.

All features

What is included

Files and links

  • File upload or external URL
  • Icons for PDF, Word, Excel, PowerPoint, archives, images, video and links
  • Optional custom icon per attachment
  • Allowed extensions and maximum size in the configuration
  • Script and executable files always rejected

Assignment

  • Attachments section in the product edit form
  • Upload new files inline from the product form
  • Categories (all products in the category)
  • SKU list in the attachment form
  • Assign Attachment and Remove Attachment in the product grid

Access

  • Store views and customer groups
  • Sign-in required, with a sign-in link for guests
  • Only customers who bought the product
  • Downloads through a controller that hides the real path
  • Download counter per attachment

Customers and admin

  • My Account > Product Downloads for buyers
  • Optional links in order confirmation emails
  • Luma tab and Hyvä section
  • Separate ACL permissions
  • CLI: list attachments and clean up unused files

Feature tour

Everything your shoppers and your team see

01 / 07

A Downloads tab with icons, sizes and notes

Each file shows a type icon, title, type and size and an optional description. Files that need sign-in or a purchase say so.

02 / 07

Native Hyvä section

On Hyvä the files are listed in a Downloads section of the product details, styled with Tailwind.

03 / 07

Readable on phones

The file cards stack into one column on small screens, on Luma (left) and Hyvä (right).

04 / 07

Documents for bought products

My Account > Product Downloads lists the files of every product the customer has ordered, grouped by product.

05 / 07

All files in one grid

Type, status, assignments, sign-in and buyer settings, sort order and the number of downloads per attachment.

06 / 07

Who can see and download each file

Store views, customer groups, sign-in required, only customers who bought the product, and assignment by category or SKU list.

07 / 07

Attach files while you edit the product

Add existing attachments from a grid, change their order, remove them, or upload new files directly in the product form.

Live demo

Try it before you install it

A full Magento store with the module installed, on Luma and on Hyvä. The admin demo signs you in with one click.

Compatibility

Requirements and compatibility

Compatibility of Product Attachments
Latest version 1.2.2 · 9 Oct 2026
composer.json requires php ~8.2.0||~8.3.0||~8.4.0||~8.5.0 magento/framework ~103.0.7 softaware/module-core ^1.0 magento/module-backend * magento/module-catalog * magento/module-config * magento/module-customer * magento/module-media-storage * magento/module-sales * magento/module-store * magento/module-ui *

Installation

Up and running in minutes

After you buy, create a Composer key in your account. Then, in the root of your Magento project:

  1. 01Add the repository and your key (once per project)

    composer config repositories.softaware composer https://repo.softawarecommerce.com
    composer config --auth http-basic.repo.softawarecommerce.com PUBLIC_KEY PRIVATE_KEY
  2. 02Install the module

    composer require softaware/module-product-attachments
  3. 03Enable it

    bin/magento setup:upgrade
    bin/magento setup:di:compile
    bin/magento setup:static-content:deploy
    bin/magento cache:flush

    The last three are only needed in production mode.

Prefer a zip? Every version you are entitled to can be downloaded from My modules. More about Composer access

User guide

How to set up and use Product Attachments

For version 1.2.2. The same guide comes with the module, in docs/user-guide.md.

Add downloadable files and links (manuals, data sheets, certificates, size charts, videos) to your products. They are listed in a Downloads tab on Luma and a Downloads section on Hyvä, with optional sign-in, customer group and buyers-only restrictions. This guide covers installation, configuration and day-to-day use.

Downloads tab on a Luma product page
Downloads tab on a Luma product page

1. Requirements

MagentoOpen Source or Adobe Commerce 2.4.7 to 2.4.9
PHP8.2 to 8.5
ThemesLuma and themes based on it; Hyvä (tested with Hyvä 1.5 and the default theme 3.0)
Othersoftaware/module-core (installed automatically)

The checkout is not changed.

2. Installation

Install with Composer from the SoftAware Commerce repository. The access keys are in your account; see Composer access.

composer config repositories.softaware composer https://repo.softawarecommerce.com
composer config --auth http-basic.repo.softawarecommerce.com PUBLIC_KEY PRIVATE_KEY
composer require softaware/module-product-attachments
bin/magento setup:upgrade
bin/magento setup:di:compile            # production mode only
bin/magento setup:static-content:deploy # production mode only
bin/magento cache:flush

Hyvä: the module registers itself for Hyvä's Tailwind build (view/frontend/tailwind/tailwind-source.css). After installing, rebuild your theme CSS (npm run build in the theme's web/tailwind folder). Luma loads its own small CSS file.

To update later: composer update softaware/module-product-attachments, then the same bin/magento commands.

3. Quick start

  1. Go to Softaware > Product Attachments > Manage Attachments and click Add New Attachment.
  2. Enter a Title (shown to customers), choose Source: File upload and upload a PDF.
  3. Under Visibility, keep All Store Views and leave Customer Groups empty for everybody.
  4. Under Products and Categories, enter one or more SKUs or choose a category.
  5. Click Save Attachment and open one of the products: the file is in the Downloads tab.

4. Managing attachments

Manage Attachments grid
Manage Attachments grid

Softaware > Product Attachments > Manage Attachments lists every attachment with its file or URL (with type icon and size), type, status, the products and categories it is assigned to, Sign-in Required, Show to Buyers, sort order, number of downloads and the last update. Mass actions: Enable, Disable and Delete (deleting an attachment also deletes its stored file).

Attachment settings

FieldWhat it does
TitleShown to customers, for example "Assembly instructions".
DescriptionOptional short text under the title.
EnabledSwitches the attachment on or off.
SourceFile upload or External URL (http or https only).
FileThe uploaded file. Allowed types and the maximum size come from the configuration.
External URLThe link target for URL attachments.
Custom IconOptional JPG, PNG, GIF or WebP image. Without it, the file type icon is used (PDF, Word, Excel, PowerPoint, archive, image, video, text or link).
Sort OrderLower numbers are listed first.
Visibility and assignment
Visibility and assignment

Visibility

FieldWhat it does
Store ViewsThe store views where the attachment is shown.
Customer GroupsLeave empty for all customer groups. Other groups do not see the file and cannot download it.
Sign-in Required to DownloadGuests see the file with a "Sign in to download" note (or not at all, see the configuration) and are sent to the sign-in page when they click it.
Only Customers Who Bought the ProductOnly signed-in customers with an order (not cancelled) for a product of this attachment can download it. The product page shows the file with the note "For customers who have bought this product"; others are sent back with a message, guests to the sign-in page. Buyers find it in My Account > Product Downloads.
Show to BuyersLists the attachment in My Account > Product Downloads (and in order emails, if enabled) for customers who ordered the product.

Products and Categories

FieldWhat it does
CategoriesAll products directly in these categories get the attachment (not products of child categories).
Product SKUsOne SKU per line, or comma-separated. Unknown SKUs are reported when you save.

5. Assigning attachments to products

Besides the SKU list and categories in the attachment form, there are two more ways:

Product edit form. Catalog > Products > edit a product > Attachments shows the attachments assigned directly to the product. Add Existing Attachments opens a grid to pick from; drag rows to change their order and click Remove to unassign one. Under New Files, Upload New File lets you add a title and a file; the attachment is created and assigned when you save the product. Attachments assigned through categories are shown on the storefront too, but are managed under Softaware > Product Attachments.

Attachments section in the product form
Attachments section in the product form

Product grid. Select products in Catalog > Products, open Actions and choose Assign Attachment or Remove Attachment, then the attachment. Remove Attachment only removes direct assignments.

6. What your customers see

Product page. On Luma the files are in a tab (default title "Downloads") in the product details tabs; on Hyvä they are in a Downloads section of the product details. Each file shows its icon, title, type and size (for example "PDF, 471 KB") and the description. Files that need sign-in show "Sign in to download"; buyers-only files show "For customers who have bought this product".

Downloads section on Hyvä
Downloads section on Hyvä

Downloads. Clicking a file opens productattachments/download/file/id/<id>. The controller checks that the attachment is enabled and visible in the store view, the customer group, sign-in and (for buyers-only files) the purchase, adds one to the download counter and then streams the file or redirects to the external URL. Guests who need to sign in are sent to the sign-in page.

My Account. Product Downloads lists the attachments marked Show to Buyers or Only Customers Who Bought the Product for every product the customer has ordered (cancelled orders are left out), grouped by product.

Product Downloads in My Account
Product Downloads in My Account

Order emails. When Add Download Links to Order Emails is on, the "Show to Buyers" attachments are listed below the items in order confirmation emails. Files that need sign-in still ask guests to sign in.

Mobile. The file cards stack into one column on phones (Luma left, Hyvä right):

Downloads on mobile, Luma and Hyvä
Downloads on mobile, Luma and Hyvä

7. Configuration

Stores > Configuration > Softaware > Product Attachments (also under Softaware > Product Attachments > Configuration).

General (default, website and store view scope)

SettingWhat it does
EnabledWhen set to No, attachments are not shown and cannot be downloaded on the storefront. Default: Yes.
Product Page Tab TitleTitle of the tab or section that lists the files. Default: Downloads.
Tab Sort OrderPosition among the product page tabs; Description is -20 and More Information -10 in the default themes. Default: 30.
Show File Size and TypeShows, for example, "PDF, 1.2 MB" next to each file. Default: Yes.
Show "Sign in to Download" Files to GuestsYes: guests see files that require sign-in, with a sign-in link. No: these files are hidden from guests. Default: Yes.

File Uploads (default scope)

SettingWhat it does
Allowed File ExtensionsComma-separated, for example pdf,docx,zip. Default: pdf,doc,docx,xls,xlsx,ppt,pptx,odt,ods,odp,rtf,txt,csv,zip,jpg,jpeg,png,gif,webp. Executable and script files are always rejected.
Maximum File Size (MB)Default: 20. PHP's upload_max_filesize and post_max_size must allow this size too.

Downloads for Bought Products (default, website and store view scope)

SettingWhat it does
Show in My AccountAdds the Product Downloads page to the customer account. Default: Yes.
My Account Link TitleName of that page in the account menu. Default: Product Downloads.
Add Download Links to Order EmailsLists the "Show to Buyers" attachments below the items in order confirmation emails. Default: No.

8. Files and security

  • Uploaded files are stored in var/softaware_attachments with random names, outside the public web root. The real path is never shown; direct requests to the storage folder are not possible.
  • Script and executable types are always rejected on upload, whatever the allowed list says, for example php, phtml, phar, html, htm, svg, js, xml, exe, sh, bat, jar, msi and dll.
  • Download file names keep letters outside ASCII; quotes, semicolons and control characters are replaced.
  • A daily cron job (03:40, softaware_product_attachments_cleanup) removes abandoned uploads older than a day.

9. Command line

bin/magento softaware:product-attachments:list                # all attachments with assignments and download counts
bin/magento softaware:product-attachments:list --sku=24-MB02  # only attachments of one product (direct or via category)
bin/magento softaware:product-attachments:cleanup --dry-run   # list abandoned uploads and stored files no attachment uses
bin/magento softaware:product-attachments:cleanup             # delete them

10. Permissions (ACL)

In System > Permissions > User Roles > Role Resources:

ResourceAllows
Softaware > Product Attachments (Softaware_ProductAttachments::attachments)View the Manage Attachments grid and forms.
Edit and Assign Attachments (Softaware_ProductAttachments::attachments_save)Create, edit, enable and disable attachments, upload files, the Attachments section of the product form and the product grid mass actions.
Delete Attachments (Softaware_ProductAttachments::attachments_delete)Delete attachments.
Stores > Configuration > Softaware Product Attachments (Softaware_ProductAttachments::config)The configuration section.

11. Troubleshooting

ProblemSolution
The Downloads tab does not appearCheck General > Enabled, that the attachment is enabled, assigned to the product (or a category the product is directly in) and visible for the store view and customer group. Flush the cache.
"Files of type ... are not allowed"Add the extension under File Uploads > Allowed File Extensions. Script and executable types cannot be allowed.
Upload of a large file failsRaise Maximum File Size (MB) and PHP's upload_max_filesize and post_max_size.
A customer cannot download a buyers-only fileThe customer must be signed in and have an order (not cancelled) for a product of the attachment. Guest orders do not count.
Downloads section unstyled on HyväRebuild the theme CSS (npm run build in the theme's web/tailwind folder) and flush the cache.
Downloads return 404 on a multi-server setupvar/softaware_attachments must be shared between the web servers.

12. Uninstall

bin/magento module:disable Softaware_ProductAttachments
composer remove softaware/module-product-attachments
bin/magento setup:upgrade

The tables softaware_product_attachment, softaware_product_attachment_store, softaware_product_attachment_customer_group, softaware_product_attachment_product and softaware_product_attachment_category and the files in var/softaware_attachments (and custom icons in pub/media/softaware/attachments/icons) are not deleted by these commands; remove them by hand if you no longer need them.

Changelog

Release notes

1.2.2

Latest
  • docs/listing.json, docs/faq.md, docs/user-guide.md and screenshots in docs/images/ (Luma, Hyvä, mobile, My Account and admin) for the product page on softawarecommerce.com.

1.2.1

  • Admin polish. Manage Attachments grid: one-line introduction, status shown as an Enabled/Disabled badge (was "Enable"/"Disable"), and an empty state with "Add Your First Attachment" instead of an empty table. The form's "Active" switch is now "Enabled".
  • Settings: every field says its default, "Use system value" is available on all fields, the tab title and the My Account link title must not be empty, and the tab sort order is validated as a number.

1.2.0

  • Requires softaware/module-core instead of softaware/module-base. The admin menu and ACL now sit under Softaware_Core::core ("Softaware"); roles that had access keep it (migrated by module-core). After updating all SoftAware modules, softaware/module-base can be removed.

1.1.0

  • "Only Customers Who Bought the Product" option: the file can only be downloaded by signed-in customers with a (not cancelled) order for a product the attachment belongs to. Shown with a note on the product page (Luma and Hyvä) and listed in My Account > Product Downloads and in order emails. New column buyers_only (default 0).
  • Switching an attachment from a file to an external URL left the stored file on disk; it is now removed.
  • More extensions are always rejected on upload (php6, phtm, pgif, inc, hta, xht, mht, mhtml, shtm, swf, ini, cjs, wasm, scr, lnk), whatever the configuration says.

1.0.0

  • First release: attachments with file upload or URL, icons, store view and customer group visibility, sign-in requirement, product/category/mass assignment, product form section with inline upload, storefront downloads tab for Luma and Hyvä, download controller with counter, My Account page and optional order email links, CLI commands.

FAQ

Questions, answered

Something else on your mind? The developers who wrote the module answer before and after you buy.

Ask a question →

Already installed it? Open a support ticket

What can I attach to a product?

Uploaded files (by default PDF, Word, Excel, PowerPoint, OpenDocument, RTF, TXT, CSV, ZIP and images) or a link to an external URL, such as a video or a manufacturer's page. You choose the allowed extensions and the maximum file size in the configuration.

Does it work with Hyvä?

Yes. On Hyvä the files are listed in a Downloads section of the product details; on Luma they are in a Downloads tab next to Details and More Information. The module registers itself for Hyvä's Tailwind build, so rebuild your theme CSS once after installing.

How do I assign an attachment to many products?

Four ways: in the attachment form by SKU list (one per line or comma-separated) or by category (all products directly in the category), in the product edit form (Attachments section), or with Assign Attachment in the product grid's Actions menu.

Can I restrict a file to signed-in customers or some customer groups?

Yes. Sign-in Required to Download sends guests to the sign-in page when they click the file. You decide whether guests see these files with a "Sign in to download" note or not at all. Customer Groups limits a file to the selected groups; other groups do not see it and cannot download it.

Can only customers who bought the product download a file?

Yes, with Only Customers Who Bought the Product. Only signed-in customers with an order (not cancelled) for a product of the attachment can download it. The product page lists the file with the note "For customers who have bought this product", the same for every visitor, so the page stays cacheable. Guest orders cannot unlock the file.

Where do customers find documents after they have bought a product?

Under My Account > Product Downloads (the title can be changed). It lists the attachments marked Show to Buyers or Only Customers Who Bought the Product for every product the customer has ordered. Download links can also be added below the items in order confirmation emails.

Can customers see where the files are stored?

No. Files are stored in var/softaware_attachments with random names, outside the public web root, and every download goes through a controller that checks status, store view, customer group, sign-in and purchase before it streams the file.

Which file types are blocked?

Script and executable types (for example php, phtml, html, svg, js, exe, sh and xml) are always rejected, whatever the allowed list in the configuration says.

Do I see how often a file was downloaded?

Yes. Each download through the storefront adds one to the attachment's counter, shown in the Downloads column of the Manage Attachments grid and in bin/magento softaware:product-attachments:list.

Does an attachment on a category also apply to its subcategories?

No. Category assignments apply to products directly assigned to the category, not to products in child categories.

Is the upload size limited by anything else?

Yes. PHP's upload_max_filesize and post_max_size must allow the size you set under Maximum File Size (MB).

Does it work on a multi-server setup?

The files are stored in var/softaware_attachments. On several web servers this folder must be shared, or a developer can point the module's file storage to another shared directory in di.xml.

Support

Help from the developers who wrote it

From the blog

Guides and articles