Configure the RepositoryAuthenticationProvider

AuthenticationProvider Configuration

When using JAAS login, authenticated users are assigned the everybody role by default. For more granular control over user permissions, configure role mapping as described in Delivery Tier Authorization Configuration.

You can manage user roles by configuring the org.hippoecm.hst.security.impl.RepositoryAuthenticationProvider. This is the default implementation of the org.hippoecm.hst.security.AuthenticationProvider. For details on customizing the authentication provider, see Customize the Delivery Tier's Authentication Provider.

The RepositoryAuthenticationProvider supports several configuration properties. You can override these settings for each HST site web application in its hst-config.properties file. For more information, see HST-2 Container Configuration.

### Hippo Login Module Authentication Provider configurations ###
## default properties for the RepositoryAuthenticationProvider ##
# optional required userrole to be allowed to authenticate
security.authentication.required.userrole =
# default excluded standard provided userroles (prefixed with xm.)
security.authentication.excluded.userrole.prefixes = xm.
# , delimiter separating multiple excluded userrole prefixes
security.authentication.excluded.userrole.prefixes.delimiter= ,
# default include only standard provided userroles (prefixed with xm.): effectively by default don't include any!
security.authentication.included.userrole.prefix = xm.
# by default strip the userrole prefix (if any) from the mapped role name
security.authentication.strip.included.userrole.prefix = true
# prefix to be added to produced role names (default no prefix added)
security.authentication.role.prefix =
## common/shared properties for all Authentication Provider beans ##
# default role to be added to anyone authenticated (if not already added): to be specified *without* possible role.prefix
security.authentication.default.role = everybody
## properties only used for the deprecated jcrAuthenticationProvider/HippoAuthenticationProvider ##
# the default domain name to use for querying and resolving role mappings
security.authentication.role.domain = everywhere

By default, this configuration does not map any user roles because both the excluded and included prefixes are set to xm.. However, the default role everybody is always assigned to authenticated users.

To enable role mapping in addition to authentication, you must override specific configuration properties. For guidance, refer to Delivery Tier Authorization Configuration.

Example Usage

Consider a test project with the following overrides in its hst-config.properties file:

security.authentication.required.userrole = hst.site.user
security.authentication.included.userrole.prefix = site.

With this configuration:

  • Only users with the hst.site.user user role can authenticate.
  • Only user roles that start with the site. prefix are mapped to role principals.

The following YAML bootstrap configuration sets up the required user roles and assignments:

definitions: config: /hippo:configuration/hippo:userroles: /hst.site.user: jcr:primaryType: hipposys:userrole /site.admin: jcr:primaryType: hipposys:userrole /xm.cms.user: hipposys:userroles: operation: add value: [hst.site.user] /hippo:configuration/hippo:users/admin: hipposys:userroles: operation: add value: [site.admin] /hippo:configuration/hippo:groups/admin: hipposys:userroles: operation: add value: [site.admin]

This configuration defines:

  1. The user role hst.site.user
  2. The user role site.admin
  3. The user role xm.cms.user, which inherits hst.site.user
  4. The admin user and group, both assigned the site.admin user role

With this setup, you can enforce HST role-based security. For example, restrict access to a specific sitemap item as follows:

definitions: config: /hst:hst/hst:configurations/demosite/hst:sitemap: jcr:primaryType: hst:sitemap /test: jcr:primaryType: hst:sitemapitem hst:authenticated: true hst:roles: [admin]

In this example, the /test sitemap item requires authentication. Only users with the admin role principal can access it. The admin user receives the admin role principal because:

  1. The user has the site.admin user role.
  2. The configuration sets security.authentication.included.userrole.prefix = site..

With the site. prefix, only user roles starting with site. are included. The prefix is stripped, so the site.admin user role maps to the admin role.

Modify the Default Added Role

By default, all authenticated users are assigned the everybody role. To change this to another role, such as siteusers, set the following property in your hst-config.properties file:

security.authentication.default.role = siteusers

If you change the default role, also update the servlet configuration as described in Delivery Tier Authentication to replace everybody with siteusers.

Share Feedback
Page: /about/security/core-security/configure-the-repositoryauthenticationprovider
Section: About
Category *