Limit Access to Specific Pages
Overview
You can restrict access to specific sections of a channel by requiring additional user roles. This allows you to enforce more granular authorization within a protected channel.
Use Case
Suppose you have already configured a preview channel with access limited to authenticated users who have the staff role. For details on this setup, see Add a Preview Channel and Limit Access.
Now, you want to further restrict access so that only users with an additional uberstaff role can access a subset of the preview, such as /blog and its subpages. Users with only the staff role should not be able to access these pages.
Implementation Steps
-
Ensure your project uses the standard archetype and includes the blogs feature.
-
In the JCR, navigate to:
/hst:myproject/hst:configurations/myproject/hst:sitemap/blog -
Add the following property to the
blogsitemap item:hst:roles = uberstaff
Result
- Any authenticated user with the
staffrole can access/mypreview. - Only users with the
uberstaffrole can access/blogand its subpaths. - Users who have the
staffrole but not theuberstaffrole will receive a 403 Unauthorized error when attempting to access/blogor any sub-URL under/blog.
Role Assignment
To grant users access to /blog, assign them to a group that includes both roles:
site.uberstaff, site.staff
Alternatively, you can assign the uberstaff role directly to individual users as needed.
Verification
- Attempt to access
/blogas a user with only thestaffrole. Access should be denied (403). - Attempt to access
/blogas a user with bothstaffanduberstaffroles. Access should be granted.