How to block anonymous and admin user to create JCR Nodes?

Avatar

Avatar

huangb8

Avatar

huangb8

huangb8

07-05-2020

How to block anonymous and admin user to create JCR Nodes?

 

Much appreciate all the help in advance!

anonymous JCR

Accepted Solutions (1)

Accepted Solutions (1)

Avatar

Avatar

Ankur_Khare

MVP

Avatar

Ankur_Khare

MVP

Ankur_Khare
MVP

07-05-2020

Anonymous users can't create nodes.

If you want to do the same for any other group kindly assign read level permission from useradmin to that user.

Answers (2)

Answers (2)

Avatar

Avatar

Theo_Pendle

MVP

Avatar

Theo_Pendle

MVP

Theo_Pendle
MVP

08-05-2020

Hi @huangb8 ,

As @Ankur_Khare said, the anonymous should not be able to create or in any way modify nodes in the JCR. If that is currently possible on your instance, then someone either screwed up massively or you're the victim of a serious hack!

However, if you are (for some reason) in a situation where the anonymous user (aka: visitors to your AEM website) can use the API to modify nodes, you should head over to /useradmin an remove any non-READ access! 

Regarding the admin user, @Andrew_Khoury is right to say that this is a special user meant for (you guessed it) instance administration. This is the user you should give to your system admin or infrastructure department. If you are worried about developers using the admin user, you can change the password like so and give the password to the responsible party in your organisation (or preferably let them change the password).

Avatar

Avatar

Andrew_Khoury

Employee

Avatar

Andrew_Khoury

Employee

Andrew_Khoury
Employee

07-05-2020

You cannot block admin from creating, modifying or deleting nodes.  User "admin" bypasses all system permission checks.  It would be best to just not share the admin user password with your team.

 

As @huangb8 said, anonymous user cannot create nodes.