Groups

A group is a collection of users who share a common organizational or functional responsibility. When a user is a member of a group, the user automatically inherits all user roles assigned to the group, as well as any roles granted to the group within specific security domains.

Groups Configuration

Groups are stored in the repository at /hippo:configuration/hippo:groups, as child nodes of hipposys:groupfolders. Group folders can be nested, similar to user folders. Each group is represented by a single node, with the node name matching the group name. Group members are listed in the multi-valued property hipposys:members, referencing each member by their user node name.

Note:
The group node type includes a hipposys:groups property, but nested groups are not supported.

You can manage groups directly in the CMS or synchronize them with an external source such as LDAP. For groups managed in the CMS, use the hipposys:group node type. For groups managed externally, use the hipposys:externalgroup node type. The hipposys:securityprovider property identifies the security provider for the group. For CMS-managed groups, this value is internal.

To mark a group as a system group, set the hipposys:system property to true. System groups are protected and do not appear in the CMS setup management UI.

Node Type Definitions

hipposys:group

[hipposys:group] > nt:base - hipposys:securityprovider (string) = 'internal' mandatory autocreated - hipposys:system (boolean) - hipposys:members (string) multiple - hipposys:groups (string) multiple - hipposys:description (string) - hipposys:userroles (string) multiple
NameTypeRequiredDescription
node nameStringyesThe group name.
hipposys:systemBooleannoIndicates if the group is a system group. System groups are hidden from group management in Bloomreach Content.
hipposys:membersStringyesThe usernames of users who are members of the group. Each value contains one username.
hipposys:groupsStringnoNot used or implemented.
hipposys:descriptionStringnoDescription of the group.
hipposys:userrolesStringnoUser roles assigned to the group.

hipposys:externalgroup

[hipposys:externalgroup] > hipposys:group - hipposys:syncdate (date) - * (string)

hipposys:groupsfolder

[hipposys:groupfolder] > nt:base + * (hipposys:group) = hipposys:group + * (hipposys:groupfolder) = hipposys:groupfolder

Example Group Configuration

/hippo:configuration: /hippo:groups: /admin: jcr:primaryType: hipposys:group hipposys:members: [ admin ] hipposys:userroles: [ xm.default-user.system-admin ] /mygroup: jcr:primaryType: hipposys:group hipposys:members: [ ann, robbert, mary ] hipposys:userroles: [ my.author ]

Default Provided Groups

nameuserrolememberssystemdescription
authorxm.default-user.authornoMembers can edit content.
editorxm.default-user.editornoMembers can edit and (de)publish content.
webmasterxm.default-user.webmasternoMembers can edit HST configuration and configure channels.
adminxm.default-user.system-admin xm.repository-browser.usernoMembers have all privileges.
cms-adminxm.default-user.cms-adminnoMembers have CMS administrative privileges.
everybody*yesEvery logged-in user is automatically a member of this group.
Share Feedback
Page: /about/for-architects/security-architecture/groups
Section: About
Category *