Check a User's Permissions on a Node
Overview
This page explains how to use the JCR API in Bloomreach Content to check a user's permissions on a specific repository node.
When to Use
Use this approach when you need to verify whether a particular user has specific permissions on a node in the Java Content Repository (JCR). This is relevant for custom logic in HST components or other code that interacts with the repository.
JCR API Method
The JCR API provides the Session#hasPermission(String, String) method to check if the current session has a specified permission on a given node path.
Example: Check Permissions for a User
The following example demonstrates how to check if the user author has the hippo:admin, hippo:editor, and hippo:author permissions on the node /content/documents/myproject/content/sample-document/sample-document.
To use Session#hasPermission, you must obtain a JCR session authenticated as the target user. In HST code, you can retrieve the repository component from the HST component manager and log in as the desired user. In CMS code, the repository component is obtained differently, but the permission check is the same.
String path = "/content/documents/myproject/content/sample-document/sample-document"; Repository repository = HstServices.getComponentManager().getComponent(Repository.class.getName()); try { Session session = repository.login(new SimpleCredentials("author", "author".toCharArray())); boolean hasPermission = session.hasPermission(path, "hippo:admin"); System.out.println("hasPermission hippo:admin " + hasPermission); hasPermission = session.hasPermission(path, "hippo:editor"); System.out.println("hasPermission hippo:editor " + hasPermission); hasPermission = session.hasPermission(path, "hippo:author"); System.out.println("hasPermission hippo:author " + hasPermission); } catch (RepositoryException e) { // TODO handle exception }
Expected Output
In a standard project created with the Maven archetype, this code produces the following output:
hasPermission hippo:admin false
hasPermission hippo:editor false
hasPermission hippo:author true
Verification
- The output confirms which permissions the user has on the specified node.
- Adjust the username, password, or path as needed for your use case.