Utility Servlets Packaged with Bloomreach Content

Overview

Bloomreach Content includes two utility servlets in addition to the CMS and Console applications. These servlets are enabled by default unless you use a custom WEB-INF/web.xml file or have copied the original WEB-INF/web.xml into your project.

Packaged Servlets

Bloomreach Content provides the following servlets:

  • LoggingServlet
    Default path: <context-root>/logging/
    The LoggingServlet allows you to view and adjust logging levels for specific class loggers. This servlet is not required for production, but it is useful in test environments or when troubleshooting without full system access.
    The browser interface at <context-root>/logging lets you change the log level for a specific logger.

    To change the log level for a logger defined in log4j2.xml (for example, to set <logger name="org.hippoecm.hst" level="info"> to debug), use the following request:

    <context-root>/logging/?ll=org.hippoecm.hst:DEBUG
    

    This method only works if the logger exists in log4j2.xml.

  • RepositoryServlet
    Default path: <context-root>/repository/
    The RepositoryServlet runs the content repository and provides a simple browse interface for authorized users.

    Note: For more information, see Access to CMS, Console and Repository and Query the Content Repository using XPath.

  • PingServlet
    Default path: <context-root>/ping/
    The PingServlet checks if the content repository is operational. When the repository is available, it returns:

    OK - Repository online and accessible.
    

    Note: Both the CMS (authoring) and HST (delivery) applications include a PingServlet at <context-root>/ping/.

    Recommendation: Starting with CMS 12.2, the HST (delivery) application includes a PingFilter, which is preferred over the PingServlet.

Security Considerations

You can change the deployment paths for these servlets to a restricted location, such as <context-root>/admin/repository or <context-root>/admin/logging. Use your application container to limit access to all endpoints under <context-root>/admin. Without access restrictions, these servlets are publicly accessible. Although content is protected by basic authentication, exposing information such as system memory usage may not be desirable.

To restrict access, place the servlets under a common path and configure your application container to allow access only from your intranet or require additional authentication. You can also remove the LoggingServlet entirely if it is not needed, but it can be valuable for troubleshooting.

Share Feedback
Page: /deploy/administration/general/servlets-in-use
Section: Deploy
Category *