Relevant Changes in brXM 14
This page outlines the key changes between brXM 13 and brXM 14.
Major Changes
Navapp UI
Starting with version 14, Bloomreach Content introduces the Navapp UI as part of the integration with Bloomreach Discovery in the BRX platform. Navapp enables users to switch between applications within BRX.
Security Model and Configuration
The security model and its configuration have been completely redesigned to provide a simpler and more maintainable approach to authorization. Upgrading from version 13.4 to 14.0 requires you to review and update your security configuration. Before upgrading, read the updated Security Model Concepts and the Security Configuration Overhaul. If your project uses security configurations similar to those described in the Version 13 Authentication and Authorisation Walkthroughs, also review the Version 14 Authentication and Authorisation Walkthroughs, as the configuration approach has changed significantly.
Woodstox XML Processor Version Downgrade
The Woodstox XML processing library, included as a transitive dependency of Apache CXF, has been downgraded to a lower major version in 14.0.0 compared to 13.4.0. This change results from an update in the CXF-to-Woodstox dependency. If your project uses Woodstox APIs directly, review your implementation for compatibility, as there are breaking changes in Woodstox.
Minor Changes
- Login access to the CMS, Console, and Repository Browser (servlet) now requires a dedicated userrole. If you use custom administrator accounts, assign the required userroles.
- The Reporting dashboard is no longer enabled or visible by default. To grant access, assign the
xm.report.useruserrole to the relevant users or groups. - URLRewriter is now restricted to users with administrator privileges.
- The Experience Manager Overview now displays only the channels that the logged-in user has permission to view (role
channel-viewer). - Creating a new channel now requires the
channel-adminprivilege. This privilege is not granted to the default webmaster group but to users or groups with thexm.channel.adminuserrole. You can now grant this privilege separately for each HST site.
The templatecomposer manage.changes.privileges property is obsolete and no longer used. - The Repository PingServlet and StatusServlet no longer allow anonymous session users. By default, the predefined (system)
ping-useris used. - The internal SecurityService has been refactored with API and model changes. It is no longer available from the HippoWorkspace and must be retrieved through the HippoServiceRegistry:
HippoServiceRegistry.getService(SecurityService.class); - Default read/write access for logged-in users (other than admins) has been removed. To change a user and password programmatically, use the ChangePasswordManager class, available from the new RepositorySecurityManager via the HippoWorkspace in the Repository API.
- Editors no longer have direct JCR write access on folders and document variants. Editors have JCR write access only on document variants they are currently editing (as holder).
- The Delivery Tier Authorization configuration has been updated to use the new RepositoryAuthenticationProvider and Userroles by default. If you use the community-provided HST Spring Security Support, you can continue to use the deprecated HippoAuthenticationProvider, but plan to upgrade the addon when a new version is available.
- The default configuration for the Autoexport addon now exports groups, roles, and userroles, and protects against potentially destructive security configuration.
- The Social Sharing feature, previously available through the
Sharemenu in the document editor, has been removed in version 14.0. - The default retention period for relevance data has changed. Review the defaults for SQL stores and the Elasticsearch store to determine if you need to adjust them.
- The default configuration file loading behavior for HST properties has changed. HST properties for the CMS or platform webapp are now configured in a different properties file by default. This change may affect projects using CRISP. For details, see HST Container Configuration.