Utility Servlets Packaged with Bloomreach Content
Overview
Bloomreach Content includes two utility servlets in addition to the CMS and Console applications. These servlets are enabled by default unless you use a custom WEB-INF/web.xml file or have copied the original WEB-INF/web.xml into your project.
Packaged Servlets
Bloomreach Content provides the following servlets:
-
LoggingServlet
Default path:<context-root>/logging/
The LoggingServlet allows you to view and adjust logging levels for specific class loggers. This servlet is not required for production, but it is useful in test environments or when troubleshooting without full system access.
The browser interface at<context-root>/logginglets you change the log level for a specific logger.To change the log level for a logger defined in
log4j2.xml(for example, to set<logger name="org.hippoecm.hst" level="info">to debug), use the following request:<context-root>/logging/?ll=org.hippoecm.hst:DEBUGThis method only works if the logger exists in
log4j2.xml. -
RepositoryServlet
Default path:<context-root>/repository/
The RepositoryServlet runs the content repository and provides a simple browse interface for authorized users.Note: For more information, see Access to CMS, Console and Repository and Query the Content Repository using XPath.
-
PingServlet
Default path:<context-root>/ping/
The PingServlet checks if the content repository is operational. When the repository is available, it returns:OK - Repository online and accessible.Note: Both the CMS (authoring) and HST (delivery) applications include a PingServlet at
<context-root>/ping/.Recommendation: Starting with CMS 12.2, the HST (delivery) application includes a PingFilter, which is preferred over the PingServlet.
Security Considerations
You can change the deployment paths for these servlets to a restricted location, such as <context-root>/admin/repository or <context-root>/admin/logging. Use your application container to limit access to all endpoints under <context-root>/admin. Without access restrictions, these servlets are publicly accessible. Although content is protected by basic authentication, exposing information such as system memory usage may not be desirable.
To restrict access, place the servlets under a common path and configure your application container to allow access only from your intranet or require additional authentication. You can also remove the LoggingServlet entirely if it is not needed, but it can be valuable for troubleshooting.