Enable 'Unlock Document' for Users

Important Information About YAML Walkthroughs

When a walkthrough references YAML configuration, you are expected to import this YAML into a locally running repository using the Console with auto-export enabled.
If you copy a YAML snippet directly into your project without auto-export, you must uncomment the following lines if they are present:

#.meta:category: system
#.meta:add-new-system-values: true

Auto-export automatically adds this meta information for certain properties, but the Console's YAML import does not support *.meta* lines.
You have two options when following these walkthroughs:

  1. Import the YAML snippet as-is into the Console with auto-export enabled.
  2. Copy the YAML snippet into your project and uncomment the meta information.

Overview

Objective

Allow users without administrator privileges to unlock locked documents.

Context

When a user edits a document in the CMS, the document is locked for other users until the editing session ends. This prevents concurrent edits but can block access if a user leaves a document open. By default, only administrators can unlock documents. You can configure the system to allow non-administrator users to unlock documents.
Note: Granting the unlock privilege also grants publish and unpublish privileges. Users who can unlock documents will also be able to publish and unpublish them.

Use Cases

Different scenarios require different approaches. Select the method that matches your requirements.

Use Case 1: Grant Unlock Permission to Specific Users

In a production environment, you can enable this permission by logging into the CMS as an administrator with access to the Setup dashboard. Then:

  1. Go to System > Users.
  2. Select the user.
  3. Add the following user role:
xm.content.admin 

This grants the user permission to unlock locked documents.
Caution: This approach makes the user an admin for all content, but does not grant access to Setup applications. If you want to restrict users to specific content areas, this method is not suitable. The default xm.content.admin user role applies to all documents unless you have restricted the default domain at /hippo:configuration/hippo:domains/content/content-domain. For more granular control, see Use Case 3.

Use Case 2: Grant Unlock Permission to Specific Groups

There are two scenarios for group-based permissions:

  • Group exists only in production:
    1. Go to System > Groups.
    2. Select the group.
    3. Add the following user role:
xm.content.admin 

All users in this group can now unlock documents.
Note: As with users, this grants the xm.content.admin role for all documents in the repository.

  • Group is managed via bootstrap configuration:
    1. Start your project locally with Autoexport enabled.
    2. Perform the steps above in the CMS.
    3. Review the local changes and commit them to your version control system.
    4. Deploy the changes to production.

The auto-exported YAML may look like this if you add xm.content.admin to the editor group:

definitions: config: /hippo:configuration/hippo:users/editor: hipposys:userroles: .meta:category: system .meta:add-new-system-values: true type: string value: [xm.default-user.editor, xm.content.admin]

For clarity and to avoid redefining the entire property, update it to:

definitions: config: /hippo:configuration/hippo:groups/editor: hipposys:userroles: operation: add value: [xm.content.admin]

This ensures only the new value is added.

Use Case 3: Grant Unlock Permission for Specific Content to Certain Users or Groups

If you have granted access to a specific channel for a group of editors and want those editors to unlock documents in that channel, modify the YAML configuration for the relevant domain (for example, /content-french). Update the editor authrole as follows:

/editor: jcr:primaryType: hipposys:authrole hipposys:groups: #.meta:category: system #.meta:add-new-system-values: true type: string value: [french-editor] hipposys:role: admin hipposys:users: []

This configuration grants the french-editor group the admin role for their content area.

Share Feedback
Page: /about/security/core-security/configure-the-unlock-document-for-non-admin-users
Section: About
Category *
Enable 'Unlock Document' for users | Bloomreach Content Documentation