Quick Wins
This page lists practical improvements that you can implement quickly to enhance usability, performance, maintainability, and security in your Bloomreach Content project.
- Add Manage Content and Edit Menu buttons to page components. These buttons allow users to edit content directly in the Experience manager interface.
- Allow administrators to insert HTML snippets into page templates, such as in header or footer components. This approach supports integrations like Google Analytics or temporary surveys. Always implement a content security policy to mitigate security risks from injected HTML.
- When committing new
hst:pages,hst:components, orhst:configurations, sort their child nodes alphabetically to improve maintainability. - Improve SEO by configuring the Sitemap, SEO Support, and Robots.txt plugins.
- Configure all user-facing feedback (such as form messages, error notifications, and subscription emails) through the CMS or console, rather than hardcoding them.
- Configure components that interact with external systems to load asynchronously. This prevents external calls from blocking page rendering.
- Set up delivery tier users with the minimum required permissions for features like polls and form data. Do not use default credentials such as admin/admin for any site.
- Validate all input fields to prevent cross-site scripting (XSS). Avoid allowing unrestricted wildcards in search queries, as queries like "e" can cause out-of-memory errors.
- Ensure that "Page not found" (404) pages return a 404 HTTP status code. Do not return 200 (OK) or 500 (Internal Server Error) for missing pages.
- Validate all pages and CSS against W3C standards to ensure compliance and compatibility.
- Use and extend the standard delivery tier components whenever possible. These components follow best practices and are optimized for performance.
- Set the
setLimitvalue forHstQueryto match thepageSize. UseHstQueryResult#getTotalSize()andHstQuery#setOffset(int)to implement paging. - Use debug-level logging strategically to aid troubleshooting without generating excessive log output.