HST Code and Configuration Updates

Removal of HstRequestContext#isCmsRequest

The method HstRequestContext#isCmsRequest was deprecated in version 13.2, remained deprecated in 14.0, and was removed in 14.7. Use HstRequestContext#isChannelManagerPreviewRequest instead. This replacement provides the same functionality: determining if a request is in an Experience manager preview context. The new method name more accurately describes its purpose.

When upgrading to 14.0, replace all uses of HstRequestContext#isCmsRequest with HstRequestContext#isChannelManagerPreviewRequest.

In Java, update code like:

requestContext.isCmsRequest()

to:

requestContext.isChannelManagerPreviewRequest()

In Freemarker or JSP templates, update:

<#if !hstRequest.requestContext.cmsRequest>

to:

<#if !hstRequest.requestContext.channelManagerPreviewRequest>

For additional details, see Detect Preview or Experience Manager Request Context.

Retrieving Authenticated User Information

The approach for retrieving authenticated user information has changed in version 14. In previous versions, any JCR session could read its own user node under /hippo:configuration/hippo:users and its group nodes under /hippo:configuration/hippo:groups. This allowed projects to access user attributes such as first and last name directly through JCR read access.

Starting with version 14, regular (non-admin, non-system) users can no longer read their own user and group nodes. Update your logic accordingly. Refer to Get Authenticated User for guidance on retrieving user information in version 14 and later.

Sitewriter User Permissions Restricted

The sitewriter user is part of the HST sitewriter session pool. It is intended for reading and writing specific JCR nodes, such as those under /formdata or /polldata. In versions prior to 14, the sitewriter user also had read access to folders under /content by default. This is no longer the case in version 14.

If your implementation relies on the sitewriter user having read access to content folders, this code may no longer function as expected. Instead of granting read access to the sitewriter, update your code to use the HST config user or another user with default read access to folders.

Required Annotations for Custom Experience Manager and Relevance REST Endpoints

If you have added custom endpoints to the Experience Manager REST API or Relevance REST API, these endpoints are now restricted by default. Methods in these REST endpoints are only accessible if they are annotated with either:

  1. javax.annotation.security.PermitAll, or
  2. org.hippoecm.hst.pagecomposer.jaxrs.api.annotation.PrivilegesAllowed, and the user has the required privilege for the specified JCR node.
  • Use PermitAll to allow any authenticated CMS user to invoke the method.
  • Use PrivilegesAllowed to require a specific privilege for a JCR node. The annotation accepts a privilege string and an optional absPath argument specifying the JCR node. If absPath is omitted, the system determines the node based on context (such as the currently edited HST configuration node).

For Experience (Channel) Manager REST endpoints, you can use:

  • @PermitAll
  • @PrivilegesAllowed("hippo:channel-admin")
  • @PrivilegesAllowed("hippo:channel-webmaster")
  • @PrivilegesAllowed("hippo:channel-viewer")

For Relevance endpoints, use:

  • @PrivilegesAllowed(value = "hippo:targeting-editor", absPath = /targetting:targeting/some/path)
  • @PrivilegesAllowed(value = "hippo:targeting-viewer", absPath = /targetting:targeting/some/path)

If you have custom REST endpoints integrated with the Channel Manager or Relevance (not officially supported as public API), you must add at least PermitAll or PrivilegesAllowed with the appropriate role to make the endpoint accessible.

Share Feedback
Page: /about/upgrade-guides/archived-upgrades-pre-v15/v13-v14/upgrade-hst-code
Section: About
Category *