Userroles
A userrole defines a functional privilege (also known as a functional role) that can be assigned to users directly or through group membership. Userroles and the privileges they represent are global and apply for the duration of a user's session.
Userrole Configuration
Userroles are stored in the repository at /hippo:configuration/hippo:userroles. The node name under this path specifies the userrole name.
Node Type Definitions
hipposys:userrole
[hipposys:userrole] > nt:base - hipposys:system (boolean) - hipposys:userroles (string) multiple - hipposys:description (string)
| Name | Type | Required | Description |
|---|---|---|---|
| node name | String | yes | The name of the userrole. |
hipposys:system | boolean | no | Marks the userrole as protected. System userroles cannot be modified or deleted. All standard userroles are marked as system userroles. |
hipposys:userroles | String | no | Lists other userroles that this userrole implies. |
hipposys:description | String | no | Description of the userrole. |
hipposys:userrolefolder
[hipposys:userrolefolder] > nt:base + * (hipposys:userrole) = hipposys:userrole
Standard Userrole Naming Convention
Standard userroles follow this naming pattern:
<prefix>.<feature>.<function>
For Bloomreach Content, the prefix is always xm.
Standard userroles are grouped as follows:
- Feature Access Userroles:
These userroles control access to CMS features that are not tied to specific repository content.
Naming convention:xm.<feature>.user
Examples:xm.cms.user,xm.project.user - Repository Domain Security Userroles:
These userroles grant privileges related to repository content and functionality.
Naming convention:xm.<feature>.<repository-context-role>
Examples:xm.content.editor,xm.channel.admin,xm.project.viewer - Aggregate Userroles:
These userroles imply all privileges required for standard groups and serve as a basis for custom groups, including those from LDAP.
Naming convention:xm.default-user.<group-name>
Examples:xm.default-user.editor,xm.default-user.webmaster,xm-default-user.system-adminNote: The userrole
xm-default-user.system-adminis assigned to the defaultadmingroup for legacy reasons, rather than to asystem-admingroup.
The default userroles listed below are organized according to these categories.
CMS and Console Access
To log in to the CMS or Console application, a user must have one of the following userroles:
xm.cms.user– required for CMS loginxm.console.user– required for Console login
Note: Only regular users can log in with these userroles. System users (users with
hipposys:systemset to true) cannot log in, even if they have these userroles assigned.
CMS Feature Access
CMS features can be restricted by requiring specific userroles. Most top-level CMS features are configured in the repository using frontend:plugin nodes. These plugins are loaded for a user at or after login. Many left-menu and nested features require a dedicated "feature toggle" userrole, specified by the hipposys:userrole property. For example:
/hippo:configuration/hippo:frontend/cms/hippo-channel-manager/channel-manager-perspective: jcr:primaryType: frontend:plugin frontend:appPath: experience-manager hipposys:userrole: xm.channel.user
The following CMS features require specific userroles:
-
Home:
xm.dashboard.user -
Experience Manager:
xm.channel.user -
Projects:
xm.project.user -
Content:
xm.content.user- Documents
- Document Types:
xm.system.admin - Url Rewriter:
xm.urlrewriter.admin(since v14.2) orxm.repository.admin(v14.0–14.1)
- Document Types:
- Documents
-
Document Search:
xm.advanced-search.user -
Insights
-
Content Reports:
xm.report.userThe
xm.report.useruserrole is not automatically included in any defaultxm.default-user.*userroles or groups. Assign this userrole explicitly to users or groups that require access to content reports.
-
-
Audiences
- Content Audiences:
xm.targeting.user
- Content Audiences:
-
Setup
- System:
xm.system.user- Users:
xm.security.viewer - Groups:
xm.security.viewer - Userroles:
xm.security.viewer - Permissions:
xm.security.viewer - Replication:
xm.security.admin - System Information:
xm.system.admin - System Properties:
xm.system.admin - Updater Editor:
xm.system.admin
- Users:
- Form Data:
xm.form.user
- System:
Example Userrole Configuration
/hippo:configuration: /hippo:userroles: /xm.content.user: jcr:primaryType: hipposys:userrole hipposys:system: true /xm.content.viewer: jcr:primaryType: hipposys:userrole hipposys:system: true hipposys:userroles: [ xm.content.user ] /my.content.viewer: jcr:primaryType: hipposys:userrole hipposys:userroles: [ xm.content.viewer ]
Default Userroles
| Userrole | Implied Userroles | Description |
|---|---|---|
xm.repository-browser.user | Required to log in and use the repository servlet for querying and navigating repository content. | |
xm.cms.user | xm.frontend-config.reader | Required to log in and use the CMS application. |
xm.console.user | xm.frontend-config.reader | Required to log in and use the Console application. |
xm.dashboard.user | Required to access the Home (dashboard) menu and functionality in the CMS. | |
xm.content.user | xm.advanced-search.user | Required to access the Content menu and functionality in the CMS. |
xm.report.user | Required to access Insights > Content Reports in the CMS. Not granted or implied by default; assign explicitly as needed. | |
xm.system.user | Required to access the Setup > System menu and functionality in the CMS. | |
xm.channel.user | Required to access the Experience Manager (Channels) menu and functionality in the CMS. | |
xm.targeting.user | Required to access the Audiences menu and functionality in the CMS. | |
xm.project.user | Required to access the Projects menu and functionality in the CMS. | |
xm.advanced-search.user | Required to access the Document Search menu and functionality in the CMS. | |
xm.form.user | Required to access the Setup > Form Data menu and functionality in the CMS. | |
xm.repository.admin | Grants all repository (jcr:all and hippo:admin) privileges through the admin role. | |
xm.system.admin | xm.console.user xm.repository.admin xm.security.user-admin xm.security.application-admin | Grants administration and use of system functionality and configuration, such as Document Types, Update Editor, and System Info. |
xm.security.viewer | xm.system.user | Allows viewing repository security configuration (users, groups, security domains, roles, userroles). |
xm.security.user-admin | xm.security.viewer | Allows administration of users and groups; implies xm.security.viewer. |
xm.security.application-admin | xm.security.viewer | Allows administration of security domains, userroles, and roles; implies xm.security.viewer. |
xm.content.viewer | xm.content.user | Allows viewing content through the readonly role. |
xm.content.author | xm.content.viewer | Allows authoring (create, edit, move, rename, copy, delete) of content through the author role. |
xm.content.editor | xm.content.author | Allows publishing and unpublishing content through the editor role; implies xm.content.author. |
xm.content.admin | xm.content.editor | Allows unlocking content locked by another user through the admin role; implies xm.content.editor. |
xm.repository.reader | Allows repository read access everywhere through the readonly role. | |
xm.webfiles.reader | Allows repository read access of webfiles through the readonly role. | |
xm.form.writer | Allows reading and writing of delivery tier form data through the readwrite role. | |
xm.live-documents.reader | xm.webfiles.reader | Allows reading of live (published) documents through the readonly role. |
xm.preview-documents.reader | xm.webfiles.reader | Allows reading of preview (unpublished) documents through the readonly role. |
xm.channel.admin | xm.channel.webmaster | Allows administration of channels through the channel-admin role; implies xm.channel.webmaster. |
xm.channel.webmaster | xm.channel.viewer | Allows editing and publishing channels through the channel-webmaster role; implies xm.channel.viewer. |
xm.channel.viewer | xm.channel.user xm.webfiles.reader | Allows viewing channels through the channel-viewer role; implies xm.webfiles.reader. |
xm.frontend-config.reader | Allows reading CMS and Console frontend configuration through the readonly role. | |
xm.targeting.viewer | xm.targeting.user | Allows viewing targeting configuration and data through the targeting-viewer role. |
xm.targeting.editor | xm.targeting.viewer | Allows editing targeting configuration and data through the targeting-editor role; implies xm.targeting.viewer. |
xm.project.viewer | xm.project.user | Allows viewing projects through the project-viewer role. |
xm.project.editor | xm.project.viewer | Allows editing projects through the project-editor role; implies xm.project.viewer. |
xm.project.admin | xm.project.editor | Allows administration of projects through the project-admin role; implies xm.project.editor. |
xm.default-user.author | xm.cms.user xm.dashboard.user xm.content.author xm.channel.viewer xm.project.viewer | Implies all standard userroles required for a default author user or group. |
xm.default-user.editor | xm.cms.user xm.dashboard.user xm.content.editor xm.channel.viewer xm.project.editor | Implies all standard userroles required for a default editor user or group. |
xm.default-user.webmaster | xm.cms.user xm.dashboard.user xm.channel.webmaster xm.project.editor xm.targeting.editor | Implies all standard userroles required for a default webmaster user or group. |
xm.default-user.cms-admin | xm.cms.user xm.dashboard.user xm.content.admin xm.channel.admin xm.project.admin xm.targeting.editor xm.form.user xm.repository.admin xm.security.user-admin xm.security.application-admin | Implies all standard userroles required for a default CMS administrator user or group. |
xm.default-user.system-admin | xm.cms.user xm.dashboard.user xm.content.admin xm.channel.admin xm.project.admin xm.targeting.editor xm.form.user xm.system.admin xm.security.user-admin xm.security.application-admin | Implies all standard userroles required for a default system administrator user or group. |