Customize the Delivery Tier's Authentication Provider

Overview

This page describes how to customize the AuthenticationProvider component in the delivery tier of Bloomreach Content (formerly Hippo CMS).

When to Use

Implement a custom AuthenticationProvider when you need to authenticate users against a security backend other than the default JCR repository, such as a database, LDAP, or an external security framework (for example, Spring Security's UserDetailsService).

Default AuthenticationProvider

The delivery tier uses the AuthenticationProvider component to handle user authentication and assign security roles. By default, the component is configured for repository-based authentication using the following Spring configuration:

<bean id="org.hippoecm.hst.security.AuthenticationProvider" class="org.hippoecm.hst.security.impl.RepositoryAuthenticationProvider"> <!-- SNIP --> </bean>

Implement a Custom AuthenticationProvider

To integrate with a different authentication backend, implement the org.hippoecm.hst.security.AuthenticationProvider interface. This interface defines methods for authenticating users and retrieving their security roles.

public interface AuthenticationProvider { /** * Authenticate a user. * * @param userName The user name. * @param password The user password. * @return the {@link User} */ User authenticate(String userName, char [] password) throws SecurityException; /** * Returns security roles of the given user * @param user */ Set<Role> getRolesByUser(User user) throws SecurityException; }
  • authenticate(String userName, char[] password): Authenticates the user and returns a User object if successful. Throws SecurityException on failure.
  • getRolesByUser(User user): Returns the set of security roles assigned to the specified user. Throws SecurityException on failure.

Configure the Custom AuthenticationProvider

After implementing your custom AuthenticationProvider, register it in the HST container components assembly override XML. For example:

site/components/src/main/resources/META-INF/hst-assembly/overrides/my-custom-auth-provider.xml

<bean id="org.hippoecm.hst.security.AuthenticationProvider" class="com.example.security.MyCustomAuthenticationProvider"> <!-- Configure dependencies to inject into this bean here --> </bean>

This configuration replaces the default authentication provider with your custom implementation.

Share Feedback
Page: /about/security/core-security/customize-delivery-tier-authentication-provider
Section: About
Category *