Expand my Community achievements bar.

Dive into Adobe Summit 2024! Explore curated list of AEM sessions & labs, register, connect with experts, ask questions, engage, and share insights. Don't miss the excitement.
SOLVED

How to block anonymous and admin user to create JCR Nodes?

Avatar

Level 1

How to block anonymous and admin user to create JCR Nodes?

 

Much appreciate all the help in advance!

Topics

Topics help categorize Community content and increase your ability to discover relevant content.

JCR
1 Accepted Solution

Avatar

Correct answer by
Community Advisor

Anonymous users can't create nodes.

If you want to do the same for any other group kindly assign read level permission from useradmin to that user.

View solution in original post

3 Replies

Avatar

Correct answer by
Community Advisor

Anonymous users can't create nodes.

If you want to do the same for any other group kindly assign read level permission from useradmin to that user.

Avatar

Employee

You cannot block admin from creating, modifying or deleting nodes.  User "admin" bypasses all system permission checks.  It would be best to just not share the admin user password with your team.

 

As @huangb8 said, anonymous user cannot create nodes.

Avatar

Level 10

Hi @huangb8 ,

As @Ankur_Khare said, the anonymous should not be able to create or in any way modify nodes in the JCR. If that is currently possible on your instance, then someone either screwed up massively or you're the victim of a serious hack!

However, if you are (for some reason) in a situation where the anonymous user (aka: visitors to your AEM website) can use the API to modify nodes, you should head over to /useradmin an remove any non-READ access! 

Regarding the admin user, @Andrew_Khoury is right to say that this is a special user meant for (you guessed it) instance administration. This is the user you should give to your system admin or infrastructure department. If you are worried about developers using the admin user, you can change the password like so and give the password to the responsible party in your organisation (or preferably let them change the password).