Grant Access to One Channel
Important: YAML Configuration in Walkthroughs
When following these walkthroughs, YAML configuration is intended to be imported into a locally running repository using the Console with auto-export enabled.
If you copy a YAML snippet directly into your project without auto-export, uncomment the following lines if they are present:
#.meta:category: system
#.meta:add-new-system-values: true
Auto-export automatically adds this meta information for some properties. However, the Console's YAML import does not support lines starting with .meta. You have two options:
- Import the YAML snippet as-is into the Console with auto-export enabled.
- Copy the YAML snippet into your project and uncomment the
.metalines.
Introduction
Goal
Grant a group access to a specific channel and its associated content only.
Use Case
This example uses a Bloomreach Content project created with the Maven archetype, with the News feature added, and a French translated channel added.
The project contains the following content root folders:
/content:
/documents:
/myproject:
/monprojet:
/administration:
/assets:
/myproject:
/monprojet:
/gallery:
/myproject:
/monprojet:
Info: The
myprojectandmonprojetfolders under assets and gallery are not created automatically when following Add a Translated Channel. Add them manually if needed.
You need to create two groups:
- french-authors
- french-editors
French authors require:
- Author privileges for
/content/documents/monprojet(to create French documents) - Author privileges for
/content/assets/monprojetand/content/gallery/monprojet(to upload French assets and images) - Readwrite privileges for
/content/assets/monprojetand/content/gallery/monprojet(to write to assets and images)
French editors require:
- Editor privileges for
/content/documents/monprojet(to publish French documents) - Editor privileges for
/content/assets/monprojetand/content/gallery/monprojet(to upload French assets and images) - Readwrite privileges for
/content/assets/monprojetand/content/gallery/monprojet(to write to assets and images)
Both French authors and editors must be denied access to /content/documents/myproject and /content/documents/administration.
French authors and editors should only access the French preview channel (Mon Projet) in the Experience manager.
French editors must be able to edit the French channel.
French authors must be able to preview the French channel but not edit it.
Approach
To implement these requirements, update the security configuration as follows:
- Create a French test author and a French test editor (for local development)
- Create French editor and author groups with the required user roles (configuration)
- Define a new domain for French documents, gallery, and assets, assigning author/editor roles to the French groups
- Define a new domain for French gallery and assets, assigning readwrite privileges to the French groups (required for writing to asset and gallery documents)
Prerequisites
Log in to the Console as admin and ensure that Autoexport is enabled.
Create Test Users
You can also create users using the CMS UI.
In the Console, under /hippo:configuration/hippo:users, add a French test author and editor by importing the following YAML files:
/french-author:
jcr:primaryType: hipposys:user
hipposys:active: true
hipposys:password: french-author
hipposys:securityprovider: internal
and
/french-editor:
jcr:primaryType: hipposys:user
hipposys:active: true
hipposys:password: french-editor
hipposys:securityprovider: internal
These users are not auto-exported. Manually add them to your local YAML files under /repository-data/application/src/main/resources/hcm-config.
Create the French Editor and Author Groups
You can also create groups using the CMS UI.
In the Console, under /hippo:configuration/hippo:groups, add:
/french-authors:
jcr:primaryType: hipposys:group
hipposys:members:
#.meta:category: system
#.meta:add-new-system-values: true
type: string
value: [french-author]
hipposys:securityprovider: internal
hipposys:userroles: [xm.cms.user, xm.content.user, xm.channel.user, xm.report.user, xm.dashboard.user, xm.channel.viewer]
and
/french-editors:
jcr:primaryType: hipposys:group
hipposys:members:
#.meta:category: system
#.meta:add-new-system-values: true
type: string
value: [french-editor]
hipposys:securityprovider: internal
hipposys:userroles: [xm.cms.user, xm.content.user, xm.channel.user, xm.report.user, xm.dashboard.user, xm.channel.webmaster]
Pay close attention to the userroles assigned. The default editor and author groups use only one user role: xm.default-user.editor or xm.default-user.author. Assigning these default user roles to the French groups would grant access to non-French documents, because the default user roles inherit from xm.content.author or xm.content.editor, which provide author/editor roles on the default /hippo:configuration/hippo:domains/content domain. To restrict access, explicitly define the user roles for each French group:
xm.content.userfor the Content applicationxm.channel.userfor the Experience managerxm.report.userfor Content reportsxm.dashboard.userfor the Home application
Assign xm.channel.webmaster to French editors (edit rights on the French channel) and xm.channel.viewer to French authors (view-only rights on the French channel). For more details, see default provided userroles.
After verifying the setup locally, remove the test members french-author and french-editor from the groups before deploying to production. For a cleaner setup, add user creation to the development bootstrap data and, in the main.yaml of the development module, add the users to the groups (the groups themselves are application configuration, not development):
definitions:
config:
/hippo:configuration/hippo:groups/french-authors:
hipposys:members:
operation: add
type: string
value: [french-author]
/hippo:configuration/hippo:groups/french-editors:
hipposys:members:
operation: add
type: string
value: [french-editor]
Customize Security Domains
You cannot create domains in the CMS UI, but you can assign groups and users to domains using the CMS UI.
Create a domain for the French documents, gallery items, and assets. The following domain configuration is required:
/content-french: jcr:primaryType: hipposys:domain /content-domain: jcr:primaryType: hipposys:domainrule /content-and-descendants: jcr:primaryType: hipposys:facetrule hipposys:equals: true hipposys:facet: jcr:path hipposys:type: Reference hipposys:value: /content/documents/monprojet /assets: jcr:primaryType: hipposys:domainrule /assets-french: jcr:primaryType: hipposys:facetrule hipposys:equals: true hipposys:facet: jcr:path hipposys:filter: false hipposys:type: Reference hipposys:value: /content/assets/monprojet /gallery: jcr:primaryType: hipposys:domainrule /gallery-french: jcr:primaryType: hipposys:facetrule hipposys:equals: true hipposys:facet: jcr:path hipposys:filter: false hipposys:type: Reference hipposys:value: /content/gallery/monprojet /author: jcr:primaryType: hipposys:authrole hipposys:groups: #.meta:category: system #.meta:add-new-system-values: true type: string value: [french-authors] hipposys:role: author hipposys:users: #.meta:category: system #.meta:add-new-system-values: true type: string value: [] /editor: jcr:primaryType: hipposys:authrole hipposys:groups: #.meta:category: system #.meta:add-new-system-values: true type: string value: [french-editor] hipposys:role: editor hipposys:users: #.meta:category: system #.meta:add-new-system-values: true type: string value: []
This domain ensures that French editors have the editor role and French authors have the author role for French documents, gallery items, and assets.
You also need a domain similar to /hippo:configuration/hippo:domains/non-publishable-readwrite. The author or editor role does not provide the jcr:write privilege required to write to JCR nodes. Normally, the workflow user session performs writes, but editors and authors need explicit jcr:write privilege for:
- Document drafts they hold (covered by the standard draft-document-holder-readwrite security domain)
- Image sets and assets (no drafts exist for these types)
To grant readwrite role to French editors and authors for French gallery items and assets, define the following domain:
/content-french-assets-images-readwrite: jcr:primaryType: hipposys:domain /readwrite: jcr:primaryType: hipposys:authrole hipposys:groups: #.meta:category: system #.meta:add-new-system-values: true type: string value: [french-editors, french-authors] hipposys:role: readwrite hipposys:users: #.meta:category: system #.meta:add-new-system-values: true type: string value: [] /french-assets-domain: jcr:primaryType: hipposys:domainrule /documents-only: jcr:primaryType: hipposys:facetrule hipposys:equals: true hipposys:facet: hippo:availability hipposys:type: String hipposys:value: live /non-publishable: jcr:primaryType: hipposys:facetrule hipposys:equals: false hipposys:facet: nodetype hipposys:type: String hipposys:value: hippostd:publishable /french-assets-and-descendants: jcr:primaryType: hipposys:facetrule hipposys:equals: true hipposys:facet: jcr:path hipposys:type: Reference hipposys:value: /content/assets/monprojet /french-gallery-domain: jcr:primaryType: hipposys:domainrule /documents-only: jcr:primaryType: hipposys:facetrule hipposys:equals: true hipposys:facet: hippo:availability hipposys:type: String hipposys:value: live /non-publishable: jcr:primaryType: hipposys:facetrule hipposys:equals: false hipposys:facet: nodetype hipposys:type: String hipposys:value: hippostd:publishable /french-gallery-and-descendants: jcr:primaryType: hipposys:facetrule hipposys:equals: true hipposys:facet: jcr:path hipposys:type: Reference hipposys:value: /content/gallery/monprojet
Verification
Log in to the CMS as french-author and verify the following:
You can:
- Browse the
monprojetcontent folder - Create subfolders in the
monprojetfolder - Create and edit documents in the
monprojetfolder - Upload and use images in the
monprojetgallery folder - Use images in the
myprojectgallery folder - Upload and use files in the
monprojetassets folder - Use files in the
myprojectassets folder - Request publication for documents in the
monprojettree - Preview the Mon Projet channel
- See the Mon Projet channel
You cannot:
- See the
myprojectandadministrationfolders - See the My Project channel
- Edit the Mon Projet channel
- Upload images or create subfolders in the
myprojectgallery folder - Upload files or create subfolders in the
myprojectassets folder
Repeat these checks for french-editor and also verify that this user can:
- Publish documents in the
monprojetfolder - Accept or reject publication requests in the
monprojetfolder - Edit the Mon Projet channel
Tip: After configuring access for French authors and editors, you can create similar groups for English authors and editors and grant them access to the English channel and its content only.