Limit Access to Specific Pages

Overview

You can restrict access to specific sections of a channel by requiring additional user roles. This allows you to enforce more granular authorization within a protected channel.

Use Case

Suppose you have already configured a preview channel with access limited to authenticated users who have the staff role. For details on this setup, see Add a Preview Channel and Limit Access.

Now, you want to further restrict access so that only users with an additional uberstaff role can access a subset of the preview, such as /blog and its subpages. Users with only the staff role should not be able to access these pages.

Implementation Steps

  1. Ensure your project uses the standard archetype and includes the blogs feature.

  2. In the JCR, navigate to:

    /hst:myproject/hst:configurations/myproject/hst:sitemap/blog
    
  3. Add the following property to the blog sitemap item:

    hst:roles = uberstaff

Result

  • Any authenticated user with the staff role can access /mypreview.
  • Only users with the uberstaff role can access /blog and its subpaths.
  • Users who have the staff role but not the uberstaff role will receive a 403 Unauthorized error when attempting to access /blog or any sub-URL under /blog.

Role Assignment

To grant users access to /blog, assign them to a group that includes both roles:

site.uberstaff, site.staff

Alternatively, you can assign the uberstaff role directly to individual users as needed.

Verification

  • Attempt to access /blog as a user with only the staff role. Access should be denied (403).
  • Attempt to access /blog as a user with both staff and uberstaff roles. Access should be granted.
Share Feedback
Page: /about/security/authorization-use-cases/limit-access-to-specific-pages
Section: About
Category *