Set Permissions When Using Workflow in the Delivery Tier

Overview

This page describes how to configure permissions so that the delivery tier application can perform document workflow actions using the sitewriter user.

When to Use

Configure these permissions if your delivery tier needs to persist content beans as documents through the WorkflowPersistenceManager.

By default, the sitewriter user has write access only to /formdata. To enable workflow actions on documents and folders, you must grant the sitewriter user additional privileges.

Prerequisites

Steps

1. Grant Author or Editor Privileges to the Sitewriter User

  1. In the console, navigate to /hippo:configuration/hippo:users/sitewriter.
  2. Add the required user role to the hipposys:userroles property:
    • To grant editor privileges, add xm.content.editor.
    • To grant author privileges only, add xm.content.author instead.

After adding the appropriate user role, the sitewriter user will have the necessary permissions to perform workflow actions on folders and documents.

Important:
You must restart the application for the changes to take effect. The sitewriter user is pooled and reused, so new roles are applied only after a new login.

2. (Optional) Clean Up the Auto-Exported Configuration

When you add a user role, auto-export generates a file at repository-data/application/src/main/resources/hcm-config/configuration/users/sitewriter.yaml similar to:

definitions: config: /hippo:configuration/hippo:users/sitewriter: hipposys:userroles: .meta:category: system .meta:add-new-system-values: true type: string value: [xm.form.writer, xm.content.editor]

To simplify the configuration, update sitewriter.yaml to only include the required addition:

definitions: config: /hippo:configuration/hippo:users/sitewriter: hipposys:userroles: operation: add value: [xm.content.editor]

This approach ensures that only the necessary user role is added, keeping the configuration concise.

Verification

  • Confirm that the sitewriter user can perform workflow actions on documents and folders in the delivery tier.
  • Check that the updated user roles are present in the console after restarting the application.
Share Feedback
Page: /about/security/authorization-use-cases/access-rights-when-you-want-to-use-workflow-from-the-hst
Section: About
Category *