Configure the CMS Package Resources Allowlist
Overview
This page explains how to control which package resources in the CMS web application are accessible to unauthenticated users.
When to Use
Configure the package resources allowlist when you need to:
- Make specific resources (such as those used by the login page) available to unauthenticated users.
- Add custom resources required for login or other unauthenticated access.
- Restrict access to package resources for security purposes.
Background
The Bloomreach Content web application bundles resources within Java packages. Access to these resources is managed as follows:
- Authenticated users have access to all package resources.
- Unauthenticated users can access only the resources specified in the allowlist. All other resources are denied.
The primary use case for the allowlist is the login page. Any resources required by the login page must be accessible to unauthenticated users. If you customize the login page and add custom resources, you must add those resources to the allowlist.
Version Note:
- In brXM 14.x, the property is named
whitelisted.classes.for.package.resources. - In version 15.0 and later, the property is renamed to
allowlisted.classes.for.package.resources. - The legacy property name remains in use for all 14.x releases for backward compatibility.
Allowlist Configuration
Configure the allowlist in the content repository at /hippo:configuration/hippo:frontend/settings. Use the multi-valued string property:
allowlisted.classes.for.package.resourcesin v15.x and laterwhitelisted.classes.for.package.resourcesin v14.x
The allowlist contains prefixes of fully qualified class names. A resource is accessible to unauthenticated users only if it is loaded relative to a class whose name starts with one of the prefixes in the allowlist.
Default Allowlist
brXM v15.x:
/hippo:configuration/hippo:frontend/settings - allowlisted.classes.for.package.resources = { "org.hippoecm.", "org.apache.wicket.", "org.onehippo.", "wicket.contrib." }
brXM v14.x:
/hippo:configuration/hippo:frontend/settings - whitelisted.classes.for.package.resources = { "org.hippoecm.", "org.apache.wicket.", "org.onehippo.", "wicket.contrib." }
All resources accessible to unauthenticated users with the default allowlist are also available as part of the open source distribution at https://github.com/bloomreach/brxm.
Add Custom Resources to the Allowlist
If your implementation requires additional resources to be accessible by unauthenticated users (for example, when customizing the login page), you must add the relevant class name prefixes to the allowlist.
Example:
Suppose you have a custom login plugin com.mycompany.CustomLoginPlugin that loads a custom CSS resource. To make this CSS resource accessible to unauthenticated users, add either com.mycompany. or com.mycompany.CustomLoginPlugin to the allowlist, depending on the desired level of restriction.
/hippo:configuration/hippo:frontend/settings - allowlisted.classes.for.package.resources = { "org.hippoecm.", "org.apache.wicket.", "org.onehippo.", "wicket.contrib.", "com.mycompany.CustomLoginPlugin" }
For brXM v14.x, use whitelisted.classes.for.package.resources instead of allowlisted.classes.for.package.resources.
Important:
Changes to the allowlist take effect after you restart the application.