Roles
A role defines a set of privileges that can be assigned to users, groups, or user roles within specific security domains.
Role Configuration
Roles are stored in the repository at /hippo:configuration/hippo:roles. The node name under this path determines the role name.
Each role specifies its privileges using the hipposys:privileges property. You can configure a role to include, or imply, other roles by setting the multi-value hipposys:roles property.
Security domains reference these roles through their authroles configuration.
Node Type Definitions
hipposys:role
[hipposys:role] > nt:base - hipposys:system (boolean) - hipposys:privileges (string) multiple - hipposys:roles (string) multiple - hipposys:description (string) - hipposys:jcrread (boolean) // not used - hipposys:jcrwrite (boolean) // not used - hipposys:jcrremove (boolean) // not used
| Name | Type | Required | Description |
|---|---|---|---|
| node name | String | yes | Name of the role |
hipposys:system | boolean | no | Marks the role as protected. Protected roles cannot be modified or deleted. |
hipposys:privileges | String | no | Custom or JCR standard privileges granted by this role. All standard roles are system roles. |
hipposys:roles | String | no | Other roles implied by this role |
hipposys:description | String | no | Description of the role |
hipposys:rolefolder
[hipposys:rolefolder] > nt:base + * (hipposys:role) = hipposys:role
Example Role Configuration
The following example shows how to define roles and their relationships in the repository:
/hippo:configuration: /hippo:roles: /author: jcr:primaryType: hipposys:role hipposys:privileges: [ jcr:read, hippo:author ] /editor: jcr:primaryType: hipposys:role hipposys:privileges: [ hippo:editor ] hipposys:roles: [ author ] /myrole: jcr:primaryType: hipposys:role hipposys:privileges: [ hippo:rest ] hipposys:roles: [ editor ]
Default Roles and Privileges
The following table lists the default roles provided by Bloomreach Content, the privileges they grant, and any implied roles.
| Role | Privileges | Implied roles |
|---|---|---|
author | jcr:read, hippo:author | |
editor | hippo:editor | author |
admin | jcr:all, hippo:admin | editor |
readonly | jcr:read | |
readwrite | jcr:read, jcr:write | |
modify | jcr:read, jcr:modifyProperties, jcr:addChildNodes, jcr:removeChildNodes | |
channel-viewer | hippo:channel-viewer | |
channel-webmaster | hippo:channel-webmaster | readwrite, channel-viewer |
channel-admin | hippo:channel-admin | channel-webmaster |
project-viewer | hippo:project-viewer | readonly |
project-editor | hippo:project-editor | readwrite, project-viewer |
project-admin | hippo:project-admin | project-editor |
targeting-viewer | hippo:targeting-viewer | |
targeting-editor | hippo:targeting-editor | readwrite, targeting-viewer |
index-export | index:export | |
restuser | hippo:rest |