Customize the Delivery Tier's Form Login Pages

Overview

This page describes how to configure and customize the form login and login error pages in the delivery tier of Bloomreach Content.

Configure a Custom Form Login Page for a Mount

To use a custom form login page for a mount, set the hst:formloginpage property on the mount node. For example:

hst:formloginpage: /examples/custom_form_login.jsp

If you configure a mount as protected with the following properties:

hst:authenticated: true hst:roles: everybody hst:formloginpage: /examples/custom_form_login.jsp

the delivery tier redirects unauthenticated requests to /examples/custom_form_login.jsp.

In your custom form login page, you can access the following HttpSession attributes to display the previous user name and the destination to redirect to after login:

Attribute nameExample valueCode example
org.hippoecm.hst.security.servlet.usernameadminsession.getAttribute("org.hippoecm.hst.security.servlet.username")
org.hippoecm.hst.security.servlet.destination/site/previewsession.getAttribute("org.hippoecm.hst.security.servlet.destination")

To customize the login error page, set the following session attribute in your custom form login page:

Attribute nameExample valueCode example
org.hippoecm.hst.security.servlet.loginErrorPage/examples/custom_form_login_error.jspsession.setAttribute("org.hippoecm.hst.security.servlet.loginErrorPage", "/examples/custom_form_login_error.jsp");

Note: You must set the custom form login error page attribute within your custom form login page.

Configure the Default Form Login Pages

The default form login and login error pages are provided as Freemarker templates in the hst-security-2.yy.xx.jar file.

You can override the default pages by configuring the following servlet initialization parameters. Use context-relative paths that the servlet context can dispatch.

Init Parameter NameDescriptionExample ValueDefault Value
loginFormPagePathPath to the login form page/WEB-INF/login/login_form.jsp or /WEB-INF/login/login_form.ftl or jcr:/hst:hst/.../login_form.ftlclasspath:/org/hippoecm/hst/security/servlet/login_form.ftl
loginErrorPagePath to the login error page/WEB-INF/login/login_failure.jsp or /WEB-INF/login/login_failure.ftl or jcr:/hst:hst/.../login_failure.ftlclasspath:/org/hippoecm/hst/security/servlet/login_failure.ftl

Customize the Default Form Login Pages

The default form login and login error pages are script templates located at:

TemplateLocation
Default form login pageclasspath:/org/hippoecm/hst/security/servlet/login_form.ftl
Default form login error pageclasspath:/org/hippoecm/hst/security/servlet/login_failure.ftl

To customize these templates, add your own templates with the same names to your application classpath (for example, in /WEB-INF/classes). The delivery tier will use your custom templates instead of the defaults.

Share Feedback
Page: /about/security/core-security/customize-delivery-tier-form-login-pages
Section: About
Category *
Customize the Delivery Tier's Form Login Pages | Bloomreach Content Documentation