# Content domains and upload functionality

**URL:** <https://community.bloomreach.com/t/content-domains-and-upload-functionality/2173>\
**Category:** Experience Manager (PaaS/OnPrem)\
**Created:** [October 11, 2020, 5:28am UTC](https://community.bloomreach.com/t/content-domains-and-upload-functionality/2173 "2020-10-11T05:28:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![marnix](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/marnix/32/228_2.png) [@marnix](https://community.bloomreach.com/u/marnix)\
**Post date:** [October 11, 2020, 5:28am UTC](https://community.bloomreach.com/t/content-domains-and-upload-functionality/2173/1 "2020-10-11T05:28:59Z")

</div>

Hi all,

Me again!

I’ve used example 3 from here ([Groovy Updater Script Examples - Bloomreach Experience Manager - The Fast and Flexible Headless CMS](https://documentation.bloomreach.com/12/library/concepts/update/groovy-update-script-examples.html)) combined with some documentation about the new way content domains are organised in the newer Bloomreach CMS versions to create a way for users to only see one of the content roots in /content/documents, ./gallery and ./assets.

This mostly works, I can edit documents appropriately, and only see the document roots I’d like the user to see, however when that type of user (editor role) tries to upload a file, I get the following error:

![image](https://canada1.discourse-cdn.com/flex027/uploads/bloomreach1/original/1X/4b8cf97b59c5e5513fe07544afe91c083dbc6626.png)

Is there something obvious I have misconfigured? If it is non-obivous, I could upload a few more screenshots regarding the setup of my content domains and their groups and user roles.

Any help is much appreciated!

Thanks!

Cheers,

Marnix

---

<div class="post-metadata">

**Author:** ![saimir.muco](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/saimir.muco/32/513_2.png) [@saimir.muco](https://community.bloomreach.com/u/saimir.muco)\
**Post date:** [October 11, 2020, 6:26am UTC](https://community.bloomreach.com/t/content-domains-and-upload-functionality/2173/2 "2020-10-11T06:26:26Z")

</div>

Hi Marnix,  
What version are you running?

---

<div class="post-metadata">

**Author:** ![marnix](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/marnix/32/228_2.png) [@marnix](https://community.bloomreach.com/u/marnix)\
**Post date:** [October 11, 2020, 7:11am UTC](https://community.bloomreach.com/t/content-domains-and-upload-functionality/2173/3 "2020-10-11T07:11:11Z")

</div>

Heya,

14.2.2 I believe.

Cheers,

Marnix

---

<div class="post-metadata">

**Author:** ![marnix](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/marnix/32/228_2.png) [@marnix](https://community.bloomreach.com/u/marnix)\
**Post date:** [October 11, 2020, 9:41am UTC](https://community.bloomreach.com/t/content-domains-and-upload-functionality/2173/4 "2020-10-11T09:41:56Z")

</div>

Putting the logging for the gallery classes a bit higher I get the following stack trace, which is a bit more helpful:

```auto
[INFO] [talledLocalContainer] Caused by: javax.jcr.AccessDeniedException: /content/gallery/demo/events/demoImage.jpg/demoImage.jpg/hippogallery:thumbnail/jcr:mimeType: not allowed to add or modify item
[INFO] [talledLocalContainer] at org.apache.jackrabbit.core.ItemSaveOperation.validateTransientItems(ItemSaveOperation.java:473) ~[jackrabbit-core-2.18.5-h1.jar:14.2.2]
[INFO] [talledLocalContainer] at org.apache.jackrabbit.core.ItemSaveOperation.perform(ItemSaveOperation.java:216) ~[jackrabbit-core-2.18.5-h1.jar:14.2.2]
[INFO] [talledLocalContainer] at org.apache.jackrabbit.core.session.SessionState.perform(SessionState.java:216) ~[jackrabbit-core-2.18.5-h1.jar:2.18.5-h1]
[INFO] [talledLocalContainer] at org.apache.jackrabbit.core.ItemImpl.perform(ItemImpl.java:91) ~[jackrabbit-core-2.18.5-h1.jar:14.2.2]
[INFO] [talledLocalContainer] at org.apache.jackrabbit.core.ItemImpl.save(ItemImpl.java:329) ~[jackrabbit-core-2.18.5-h1.jar:14.2.2]
[INFO] [talledLocalContainer] at org.apache.jackrabbit.core.session.SessionSaveOperation.perform(SessionSaveOperation.java:65) ~[jackrabbit-core-2.18.5-h1.jar:2.18.5-h1]
[INFO] [talledLocalContainer] at org.apache.jackrabbit.core.session.SessionState.perform(SessionState.java:216) ~[jackrabbit-core-2.18.5-h1.jar:2.18.5-h1]
[INFO] [talledLocalContainer] at org.apache.jackrabbit.core.SessionImpl.perform(SessionImpl.java:367) ~[jackrabbit-core-2.18.5-h1.jar:14.2.2]
[INFO] [talledLocalContainer] at org.apache.jackrabbit.core.SessionImpl.save(SessionImpl.java:856) ~[jackrabbit-core-2.18.5-h1.jar:14.2.2]
[INFO] [talledLocalContainer] at org.hippoecm.repository.impl.SessionDecorator.save(SessionDecorator.java:279) ~[hippo-repository-engine-14.2.2.jar:14.2.2]
[INFO] [talledLocalContainer] at org.hippoecm.frontend.plugins.gallery.GalleryWorkflowPlugin.createGalleryItem(GalleryWorkflowPlugin.java:178) ~[hippo-cms-gallery-frontend-14.2.2.jar:14.2.2]
[INFO] [talledLocalContainer] at org.hippoecm.frontend.plugins.gallery.GalleryWorkflowPlugin.access$100(GalleryWorkflowPlugin.java:78) ~[hippo-cms-gallery-frontend-14.2.2.jar:14.2.2]
[INFO] [talledLocalContainer] at org.hippoecm.frontend.plugins.gallery.GalleryWorkflowPlugin$UploadDialog.onFileUpload(GalleryWorkflowPlugin.java:103) ~[hippo-cms-gallery-frontend-14.2.2.jar:14.2.2]

```

The user (demo-author) has a membership to the group demo-author that has the following userroles assigned:

 ![image](https://canada1.discourse-cdn.com/flex027/uploads/bloomreach1/original/1X/44763c14b7bdfc081ac1ff91c8605cb4e74e5ab4.png)

Any help debugging (or letting me know a good way to go about debugging) this would be greatly appreciated!

Cheers,

Marnix

---

<div class="post-metadata">

**Author:** ![marnix](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/marnix/32/228_2.png) [@marnix](https://community.bloomreach.com/u/marnix)\
**Post date:** [October 12, 2020, 11:00am UTC](https://community.bloomreach.com/t/content-domains-and-upload-functionality/2173/5 "2020-10-12T11:00:16Z")

</div>

Hi,

Just for anyone else with a similar problem. I worked out that the xm.content.user does not have sufficient access to upload gallery items (but can do mostly anythign else, but xm.content.author and xm.content.editor do.

I’ve also worked out the reason that all content appears if I add any of the above userroles to a user’s group is, that they are part of the base content domain definition. So, after removing the readonly, author and editor access indicators from the default content domain, everything ends up being as expected.

It’s all a bit confusing, so I’m happy to have fixed it – thanks for your help!

Cheers,

Marnix

---

<div class="post-metadata">

**Author:** ![machak](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/machak/32/1298_2.png) [@machak](https://community.bloomreach.com/u/machak)\
**Post date:** [October 12, 2020, 12:18pm UTC](https://community.bloomreach.com/t/content-domains-and-upload-functionality/2173/6 "2020-10-12T12:18:46Z")

</div>

What might help in those cases is to: go to /console app and select specific node and choose:

> Node \> View Permissions  
> Than, in the modal popup, fill in the user name and lookup its permissions and compare it to other users…
