Get Authenticated User

This page explains how to access information about an authenticated (logged-in) user in Bloomreach Content. The guidance applies to both the delivery tier and the CMS application, specifically regarding how to obtain a SessionUser object.

Accessing the SessionUser

The SessionUser object (see the Repository API) contains user information associated with the current JCR session. This includes:

  • First name
  • Last name
  • Memberships (groups the user belongs to)
  • User roles
  • Additional properties (refer to the User interface in the Repository API)

Once you have a JCR session for the user, you can retrieve the SessionUser as follows:

final Session userSession = ... final SessionUser sessionUser = ((HippoSession)userSession).getUser();

The SessionUser interface extends User.

Accessing the User JCR Session in the CMS

In the CMS context, you can obtain the user's JCR session using Wicket code:

UserSession.get().getJcrSession()

Alternatively, if you are handling CMS requests through the HST (delivery tier), use:

RequestContextProvider.get().getSession();

Accessing the User JCR Session in the Delivery Tier

To access the JCR session used for rendering a page in the delivery tier, use:

RequestContextProvider.get().getSession();

Important:
The JCR session used for rendering is not always the same as the session for the authenticated user. The rendering session is only the authenticated user's session if the hst:mount is configured with:

hst:subjectbasedsession = true

Enabling hst:subjectbasedsession is generally discouraged. It disables session pooling for rendering, which increases CPU and memory usage and reduces scalability. For more information, see Delivery Tier Authentication and Authorization Support and the hst:subjectbasedsession property.

Accessing the User JCR Session When HST Uses a Pooled Rendering Session

When a user authenticates for a channel or page, rendering typically uses a pooled delivery tier session (such as liveuser), not the user's own session. To access the authenticated user's session, you must perform additional steps. The recommended approach is to impersonate the user and cache the resulting User object in the HTTP session:

final HstRequestContext requestContext = RequestContextProvider.get(); final HttpServletRequest request = requestContext.getServletRequest(); User user = (User) request.getSession().getAttribute("user"); if (user == null) { try { final Session userSession = requestContext.getSession() .impersonate(new SimpleCredentials(request.getUserPrincipal().getName(), "".toCharArray())); user = ((HippoSession) userSession).getUser(); request.getSession().setAttribute("user", user); } catch (RepositoryException e) { log.error("Failed to retrieve user from repository", e); } } if (user != null) { request.setAttribute("user", user); }

You do not need to explicitly log out the impersonated userSession. If the session is created by impersonating from a pooled delivery tier session, it is automatically logged out during request cleanup. Also, requestContext.getSession() returns a pooled session unless hst:subjectbasedsession is set to true.

Share Feedback
Page: /about/security/core-security/get-authenticated-user
Section: About
Category *
Get Authenticated User | Bloomreach Content Documentation