Users

User Configuration

Users are stored in the repository at /hippo:configuration/hippo:users, as child nodes of hipposys:userfolders. User folders can be nested. This structure is recommended when managing a large number of users (for example, over one hundred). You can organize users into subfolders, such as by the first letter of their username.

Each user is represented by a single node in the repository. The node name matches the username.

You can manage users directly in the CMS or synchronize them from an external source such as LDAP. For users managed by the CMS, use the hipposys:user node type. For users managed externally, use the hipposys:externaluser node type. The hipposys:securityprovider property specifies which security provider manages the user. For CMS-managed users, set this property to internal.

To designate a user as a system user, set the hipposys:system property to true. System users cannot log in to the CMS or the console. They are also hidden from the CMS setup management UI.

To disable a user, set the hipposys:active property to false. Disabled users cannot log in to the repository.

The hipposys:password property stores the user's password. Storing passwords in plain text is possible but discouraged. By default, the CMS uses SHA-256 to hash passwords. The hashed password is stored in the format $<hash algorithm>$<salt>$<hash>. For example:
$SHA-256$dGeytXwnqAU=$NqCe6sJcM4qAwV8166GdueUVA/TSyidpAI3Evn+y/hc

Node Type Definitions

hipposys:user

[hipposys:user] > nt:base - hipposys:securityprovider (string) = 'internal' mandatory autocreated - hipposys:active (boolean) = true mandatory autocreated - hipposys:system (boolean) - hipposys:password (string) - hipposys:passkey (string) - hipposys:lastlogin (date) - hipposys:firstname (string) - hipposys:lastname (string) - hipposys:email (string) - hipposys:previouspasswords (string) multiple - hipposys:passwordlastmodified (date) - hipposys:userroles (string) multiple
NameTypeRequiredDescription
node nameStringyesUsername.
hipposys:securityproviderStringyesSecurity provider for the user. Default is internal.
hipposys:activeBooleanyesIndicates if the user is enabled. Must be true for login.
hipposys:systemBooleannoMarks the user as a system user.
hipposys:passwordStringnoUser password, stored as plain text or hash. Hash format: $<hash algorithm>$<salt>$<hash>. Example: $SHA-256$HIlytXwnqSU=$NqCi2sJoM4qAwQ8136GYueUVA/TSyidpAI3Evn+y/hc=. Supported algorithms include MD5, SHA-1, and SHA-256. Use PasswordHelper.getHash(String password) to generate hashes.
hipposys:passkeyStringnoIf present and set to jvm://, the user is a JVM enabled user. Typically used for HST site users.
hipposys:firstnameStringnoUser's first name.
hipposys:lastnameStringnoUser's last name.
hipposys:emailStringnoUser's email address.
hipposys:userrolesStringnoUser roles assigned to the user.

hipposys:externaluser

[hipposys:externaluser] > hipposys:user - hipposys:lastsync (date) - * (string)

hipposys:userfolder

[hipposys:userfolder] > nt:base + * (hipposys:user) = hipposys:user + * (hipposys:userfolder) = hipposys:userfolder

Example User Configuration

/hippo:configuration: /hippo:users: /admin: jcr:primaryType: hipposys:user hipposys:securityprovider: internal hipposys:password: secret hipposys:active: true /myuser: jcr:primaryType: hipposys:user hipposys:securityprovider: internal hipposys:password: secret hipposys:active: true hipposys:firstname: John hipposys:lastname: Doe hipposys:email: [email protected]

Default Provided Users

NameUser RolesSystemJVM EnabledDescription
adminxm.default-user.system-admin, xm.repository-browser.usernonoDefault administrator. Has all privileges. Not a member of the admin group.
authornonoExample user for development mode. Member of the author group.
editornonoExample user for development mode. Member of the editor group.
workflowuserxm.repository.adminyesnoUsed internally by the CMS workflow.
liveuserxm.live-documents.readeryesyesUsed by the delivery tier to read live document variants.
previewuserxm.preview-documents.readeryesyesUsed by the delivery tier to read preview document variants.
sitewriterxm.form.writeryesyesUsed by the delivery tier to write to /formdata nodes or invoke workflow on documents if authorized.
configuserxm.repository.readeryesyesUsed by the delivery tier to read configuration nodes, including HST configuration.
frontend-system-userxm.frontend-config.readeryesyesUsed by the CMS and Console to read default frontend configuration for unauthenticated users.
hippo-relevancexm.default-user.webmasteryesyesUsed by the relevance feature.
ping-useryesyesUsed by the Repository ping service (servlet).
Share Feedback
Page: /about/security/core-security/users
Section: About
Category *
Users | Bloomreach Content Documentation