Users
User Configuration
Users are stored in the repository at /hippo:configuration/hippo:users, as child nodes of hipposys:userfolders. User folders can be nested. This structure is recommended when managing a large number of users (for example, over one hundred). You can organize users into subfolders, such as by the first letter of their username.
Each user is represented by a single node in the repository. The node name matches the username.
You can manage users directly in the CMS or synchronize them from an external source such as LDAP. For users managed by the CMS, use the hipposys:user node type. For users managed externally, use the hipposys:externaluser node type. The hipposys:securityprovider property specifies which security provider manages the user. For CMS-managed users, set this property to internal.
To designate a user as a system user, set the hipposys:system property to true. System users cannot log in to the CMS or the console. They are also hidden from the CMS setup management UI.
To disable a user, set the hipposys:active property to false. Disabled users cannot log in to the repository.
The hipposys:password property stores the user's password. Storing passwords in plain text is possible but discouraged. By default, the CMS uses SHA-256 to hash passwords. The hashed password is stored in the format $<hash algorithm>$<salt>$<hash>. For example:
$SHA-256$dGeytXwnqAU=$NqCe6sJcM4qAwV8166GdueUVA/TSyidpAI3Evn+y/hc
Node Type Definitions
hipposys:user
[hipposys:user] > nt:base - hipposys:securityprovider (string) = 'internal' mandatory autocreated - hipposys:active (boolean) = true mandatory autocreated - hipposys:system (boolean) - hipposys:password (string) - hipposys:passkey (string) - hipposys:lastlogin (date) - hipposys:firstname (string) - hipposys:lastname (string) - hipposys:email (string) - hipposys:previouspasswords (string) multiple - hipposys:passwordlastmodified (date) - hipposys:userroles (string) multiple
| Name | Type | Required | Description |
|---|---|---|---|
| node name | String | yes | Username. |
hipposys:securityprovider | String | yes | Security provider for the user. Default is internal. |
hipposys:active | Boolean | yes | Indicates if the user is enabled. Must be true for login. |
hipposys:system | Boolean | no | Marks the user as a system user. |
hipposys:password | String | no | User password, stored as plain text or hash. Hash format: $<hash algorithm>$<salt>$<hash>. Example: $SHA-256$HIlytXwnqSU=$NqCi2sJoM4qAwQ8136GYueUVA/TSyidpAI3Evn+y/hc=. Supported algorithms include MD5, SHA-1, and SHA-256. Use PasswordHelper.getHash(String password) to generate hashes. |
hipposys:passkey | String | no | If present and set to jvm://, the user is a JVM enabled user. Typically used for HST site users. |
hipposys:firstname | String | no | User's first name. |
hipposys:lastname | String | no | User's last name. |
hipposys:email | String | no | User's email address. |
hipposys:userroles | String | no | User roles assigned to the user. |
hipposys:externaluser
[hipposys:externaluser] > hipposys:user - hipposys:lastsync (date) - * (string)
hipposys:userfolder
[hipposys:userfolder] > nt:base + * (hipposys:user) = hipposys:user + * (hipposys:userfolder) = hipposys:userfolder
Example User Configuration
/hippo:configuration: /hippo:users: /admin: jcr:primaryType: hipposys:user hipposys:securityprovider: internal hipposys:password: secret hipposys:active: true /myuser: jcr:primaryType: hipposys:user hipposys:securityprovider: internal hipposys:password: secret hipposys:active: true hipposys:firstname: John hipposys:lastname: Doe hipposys:email: [email protected]
Default Provided Users
| Name | User Roles | System | JVM Enabled | Description |
|---|---|---|---|---|
admin | xm.default-user.system-admin, xm.repository-browser.user | no | no | Default administrator. Has all privileges. Not a member of the admin group. |
author | no | no | Example user for development mode. Member of the author group. | |
editor | no | no | Example user for development mode. Member of the editor group. | |
workflowuser | xm.repository.admin | yes | no | Used internally by the CMS workflow. |
liveuser | xm.live-documents.reader | yes | yes | Used by the delivery tier to read live document variants. |
previewuser | xm.preview-documents.reader | yes | yes | Used by the delivery tier to read preview document variants. |
sitewriter | xm.form.writer | yes | yes | Used by the delivery tier to write to /formdata nodes or invoke workflow on documents if authorized. |
configuser | xm.repository.reader | yes | yes | Used by the delivery tier to read configuration nodes, including HST configuration. |
frontend-system-user | xm.frontend-config.reader | yes | yes | Used by the CMS and Console to read default frontend configuration for unauthenticated users. |
hippo-relevance | xm.default-user.webmaster | yes | yes | Used by the relevance feature. |
ping-user | yes | yes | Used by the Repository ping service (servlet). |