Retrieving a Pooled Session
Bloomreach Content uses pooled JCR (Java Content Repository) sessions for most HST request processing. By default, rendering requests use a liveuser session from the session pool. For preview in Experience Manager, the system combines the read access of a previewuser session with the permissions of the currently logged-in CMS user. For details, see Security Delegation.
Note
If your site requires authentication and is configured withhst:subjectbasedsession = true, XM uses a session specific to the authenticated user instead of a pooled session.
Default Session Retrieval
For standard live site rendering requests, calling HstRequestContext#getSession() returns a pooled liveuser session.
For action requests (HTTP POST), the session type depends on whether the doAction method uses the @Persistable annotation. For more information, see HstComponent Persistable annotation and workflow.
If you need a different pooled JCR session than the default provided by HstRequestContext#getSession()—for example, to read HST configuration nodes—you can obtain it using the HST Spring ComponentManager.
Retrieve a Pooled JCR Session
Use the following pattern to obtain a pooled JCR session:
Repository repository = HstServices .getComponentManager() .getComponent(Repository.class.getName()); Session mySession = repository.login(credentials);
Sessions retrieved through the ComponentManager are managed by HST session pools. You do not need to explicitly log out pooled sessions; they are automatically logged out after an idle timeout. However, it is best practice to log out a pooled session as soon as you are finished with it. This immediately returns the session to the pool and reduces the risk of session pool exhaustion.
For information about non-pooled sessions, see Retrieving a non-pooled session. You must always log out non-pooled sessions manually.
Obtain Credentials for Pooled Users
To retrieve a pooled session, you need the appropriate credentials. HST provides five default session pools. You can obtain credentials for these pools as shown below:
ComponentManager mngr = HstServices.getComponentManager(); Credentials configCred = mngr.getComponent(Credentials.class.getName() + ".hstconfigreader"); Credentials liveCred = mngr.getComponent(Credentials.class.getName() + ".default"); Credentials binariesCred = mngr.getComponent(Credentials.class.getName() + ".binaries"); Credentials previewCred = mngr.getComponent(Credentials.class.getName() + ".preview"); Credentials writeCred = mngr.getComponent(Credentials.class.getName() + ".writable");
Each credentials object corresponds to a specific session pool. Use the credentials that match your required access level.