Roles

A role defines a set of privileges that can be assigned to users, groups, or user roles within specific security domains.

Role Configuration

Roles are stored in the repository at /hippo:configuration/hippo:roles. The node name under this path determines the role name.

Each role specifies its privileges using the hipposys:privileges property. You can configure a role to include, or imply, other roles by setting the multi-value hipposys:roles property.

Security domains reference these roles through their authroles configuration.

Node Type Definitions

hipposys:role

[hipposys:role] > nt:base - hipposys:system (boolean) - hipposys:privileges (string) multiple - hipposys:roles (string) multiple - hipposys:description (string) - hipposys:jcrread (boolean) // not used - hipposys:jcrwrite (boolean) // not used - hipposys:jcrremove (boolean) // not used
NameTypeRequiredDescription
node nameStringyesName of the role
hipposys:systembooleannoMarks the role as protected. Protected roles cannot be modified or deleted.
hipposys:privilegesStringnoCustom or JCR standard privileges granted by this role. All standard roles are system roles.
hipposys:rolesStringnoOther roles implied by this role
hipposys:descriptionStringnoDescription of the role

hipposys:rolefolder

[hipposys:rolefolder] > nt:base + * (hipposys:role) = hipposys:role

Example Role Configuration

The following example shows how to define roles and their relationships in the repository:

/hippo:configuration: /hippo:roles: /author: jcr:primaryType: hipposys:role hipposys:privileges: [ jcr:read, hippo:author ] /editor: jcr:primaryType: hipposys:role hipposys:privileges: [ hippo:editor ] hipposys:roles: [ author ] /myrole: jcr:primaryType: hipposys:role hipposys:privileges: [ hippo:rest ] hipposys:roles: [ editor ]

Default Roles and Privileges

The following table lists the default roles provided by Bloomreach Content, the privileges they grant, and any implied roles.

RolePrivilegesImplied roles
authorjcr:read, hippo:author
editorhippo:editorauthor
adminjcr:all, hippo:admineditor
readonlyjcr:read
readwritejcr:read, jcr:write
modifyjcr:read, jcr:modifyProperties, jcr:addChildNodes, jcr:removeChildNodes
channel-viewerhippo:channel-viewer
channel-webmasterhippo:channel-webmasterreadwrite, channel-viewer
channel-adminhippo:channel-adminchannel-webmaster
project-viewerhippo:project-viewerreadonly
project-editorhippo:project-editorreadwrite, project-viewer
project-adminhippo:project-adminproject-editor
targeting-viewerhippo:targeting-viewer
targeting-editorhippo:targeting-editorreadwrite, targeting-viewer
index-exportindex:export
restuserhippo:rest
Share Feedback
Page: /about/security/core-security/roles
Section: About
Category *