Set Permissions When Using Workflow in the Delivery Tier
Overview
This page describes how to configure permissions so that the delivery tier application can perform document workflow actions using the sitewriter user.
When to Use
Configure these permissions if your delivery tier needs to persist content beans as documents through the WorkflowPersistenceManager.
By default, the sitewriter user has write access only to /formdata. To enable workflow actions on documents and folders, you must grant the sitewriter user additional privileges.
Prerequisites
- Access to the Console as an admin user.
- Auto-export is enabled.
Steps
1. Grant Author or Editor Privileges to the Sitewriter User
- In the console, navigate to
/hippo:configuration/hippo:users/sitewriter. - Add the required user role to the
hipposys:userrolesproperty:- To grant editor privileges, add
xm.content.editor. - To grant author privileges only, add
xm.content.authorinstead.
- To grant editor privileges, add
After adding the appropriate user role, the sitewriter user will have the necessary permissions to perform workflow actions on folders and documents.
Important:
You must restart the application for the changes to take effect. The sitewriter user is pooled and reused, so new roles are applied only after a new login.
2. (Optional) Clean Up the Auto-Exported Configuration
When you add a user role, auto-export generates a file at repository-data/application/src/main/resources/hcm-config/configuration/users/sitewriter.yaml similar to:
definitions: config: /hippo:configuration/hippo:users/sitewriter: hipposys:userroles: .meta:category: system .meta:add-new-system-values: true type: string value: [xm.form.writer, xm.content.editor]
To simplify the configuration, update sitewriter.yaml to only include the required addition:
definitions: config: /hippo:configuration/hippo:users/sitewriter: hipposys:userroles: operation: add value: [xm.content.editor]
This approach ensures that only the necessary user role is added, keeping the configuration concise.
Verification
- Confirm that the
sitewriteruser can perform workflow actions on documents and folders in the delivery tier. - Check that the updated user roles are present in the console after restarting the application.