# Issue with users access across multiple channels in V14.6.0

**URL:** <https://community.bloomreach.com/t/issue-with-users-access-across-multiple-channels-in-v14-6-0/2779>\
**Category:** Experience Manager (PaaS/OnPrem)\
**Created:** [September 14, 2021, 1:52pm UTC](https://community.bloomreach.com/t/issue-with-users-access-across-multiple-channels-in-v14-6-0/2779 "2021-09-14T13:52:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yeshwanth\_Lagala](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/yeshwanth_lagala/32/777_2.png) [@Yeshwanth\_Lagala](https://community.bloomreach.com/u/Yeshwanth_Lagala)\
**Post date:** [September 14, 2021, 1:52pm UTC](https://community.bloomreach.com/t/issue-with-users-access-across-multiple-channels-in-v14-6-0/2779/1 "2021-09-14T13:52:06Z")

</div>

Hello Team,

We have multiple channels in our project where one of the user is assigned to **editor** group of **channel 1** and **author** group of **channel 2**.

While testing this use case, we have found that he is able to perform editor activities for both the channels rather than only in **channel 1**. we have tried replicating the same scenario in vanilla version of V14.6.0, same has been identified.

Could you please help us in solving this issue ?

For creating groups, users and domains we have followed the steps mentioned in below link. Please let me know if any additional change has to be performed to achieve this case.

> **[Grant Access to One Channel - Bloomreach Experience - Headless Digital...](https://documentation.bloomreach.com/14/library/concepts/security/authorization-use-cases/grant-access-to-one-channel.html)**
>
> Headless digital experience platform

Thanks,  
Yeshwanth.

---

<div class="post-metadata">

**Author:** ![leeablett](https://avatars.discourse-cdn.com/v4/letter/l/82dd89/32.png) [@leeablett](https://community.bloomreach.com/u/leeablett)\
**Post date:** [September 23, 2021, 6:48am UTC](https://community.bloomreach.com/t/issue-with-users-access-across-multiple-channels-in-v14-6-0/2779/2 "2021-09-23T06:48:48Z")

</div>

Hi there,

I have just implemented a similar requirement and it works fine. You have to be careful which userrole’s(hipposys:userrole) you assign to each authrole(hipposys:authrole) in the domain(hipposys:domain). It is also worthwhile checking your domain rules(hipposys:domainrule) are being applied correctly.

I recommend you remove all configuration(under domains) and add them back in one at a time. Once you remove everything, both test users should have no access. Also, remember that it is best to create two users that only have access to either channel. One last thing, once you have made changes to the domains security(hipposys:domainfolder), ensure you log out and log back in, with the test users.

Hope this helps

Lee

---

<div class="post-metadata">

**Author:** ![Yeshwanth\_Lagala](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/yeshwanth_lagala/32/777_2.png) [@Yeshwanth\_Lagala](https://community.bloomreach.com/u/Yeshwanth_Lagala)\
**Post date:** [September 29, 2021, 7:14am UTC](https://community.bloomreach.com/t/issue-with-users-access-across-multiple-channels-in-v14-6-0/2779/3 "2021-09-29T07:14:19Z")

</div>

@leeablett

**Project/Channel Name** : Myproject and MonProject

Attaching groups snapshots for reference. Can you please have a look at it once and let me know what went wrong in my case.

 ![myproject-editor](https://canada1.discourse-cdn.com/flex027/uploads/bloomreach1/original/2X/9/9c94cfc1fcfd1d7828f6688d1f1ed687a1fe093c.png)

 ![myproject-authr](https://canada1.discourse-cdn.com/flex027/uploads/bloomreach1/original/2X/2/28d2eb76b10dc8d3c7c998ad665a95aa3260caf9.png)

 ![monproject-editor](https://canada1.discourse-cdn.com/flex027/uploads/bloomreach1/original/2X/b/be4bce028fe32384f5a2299edd811de8f77fb966.png)

 ![monproject-author](https://canada1.discourse-cdn.com/flex027/uploads/bloomreach1/original/2X/2/2fa53fd3d47ae36ffebcaa17607f103d0c5f8353.png)

**MON Project Domain**

definitions:  
config:  
/hippo:configuration/hippo:domains/content-mon:  
jcr:primaryType: hipposys:domain  
/content-domain:  
jcr:primaryType: hipposys:domainrule  
/content-and-descendants:  
jcr:primaryType: hipposys:facetrule  
hipposys:equals: true  
hipposys:facet: jcr:path  
hipposys:type: Reference  
hipposys:value: /content/documents/monproject  
/author:  
jcr:primaryType: hipposys:authrole  
hipposys:groups:  
.meta:category: system  
.meta:add-new-system-values: true  
type: string  
value: [monproject-author]  
hipposys:role: author  
hipposys:users:  
.meta:category: system  
.meta:add-new-system-values: true  
type: string  
value: []  
/editor:  
jcr:primaryType: hipposys:authrole  
hipposys:groups:  
.meta:category: system  
.meta:add-new-system-values: true  
type: string  
value: [monproject-editor]  
hipposys:role: editor  
hipposys:users:  
.meta:category: system  
.meta:add-new-system-values: true  
type: string  
value: []

**MY Project Domain**

definitions:  
config:  
/hippo:configuration/hippo:domains/content-my:  
jcr:primaryType: hipposys:domain  
/content-domain:  
jcr:primaryType: hipposys:domainrule  
/content-and-descendants:  
jcr:primaryType: hipposys:facetrule  
hipposys:equals: true  
hipposys:facet: jcr:path  
hipposys:type: Reference  
hipposys:value: /content/documents/myproject  
/author:  
jcr:primaryType: hipposys:authrole  
hipposys:groups:  
.meta:category: system  
.meta:add-new-system-values: true  
type: string  
value: [myproject-author]  
hipposys:role: author  
hipposys:users:  
.meta:category: system  
.meta:add-new-system-values: true  
type: string  
value: []  
/editor:  
jcr:primaryType: hipposys:authrole  
hipposys:groups:  
.meta:category: system  
.meta:add-new-system-values: true  
type: string  
value: [myproject-editor]  
hipposys:role: editor  
hipposys:users:  
.meta:category: system  
.meta:add-new-system-values: true  
type: string  
value: []

Please note , i have created a user “mon-editor” and i have assigned monproject-editor and myproject-author groups to the user. attaching snapshot for reference

 ![CMS_User](https://canada1.discourse-cdn.com/flex027/uploads/bloomreach1/original/2X/9/9a60d0ab6b060bfd7324f37ba7bf4d05dbe46048.png)

Please let me know if you need any further information.

---

<div class="post-metadata">

**Author:** ![Yeshwanth\_Lagala](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/yeshwanth_lagala/32/777_2.png) [@Yeshwanth\_Lagala](https://community.bloomreach.com/u/Yeshwanth_Lagala)\
**Post date:** [September 29, 2021, 11:30am UTC](https://community.bloomreach.com/t/issue-with-users-access-across-multiple-channels-in-v14-6-0/2779/4 "2021-09-29T11:30:32Z")

</div>

@leeablett

I have replicated the same scenario by adding “english-authors” group to the french-editor user in go green project.  
Please find below link -[https://cms.demo.onehippo.com/](https://cms.demo.onehippo.com/)

---

<div class="post-metadata">

**Author:** ![jeroen.hoffman](https://yyz1.discourse-cdn.com/flex027/user_avatar/community.bloomreach.com/jeroen.hoffman/32/43_2.png) [@jeroen.hoffman](https://community.bloomreach.com/u/jeroen.hoffman)\
**Post date:** [September 30, 2021, 9:01am UTC](https://community.bloomreach.com/t/issue-with-users-access-across-multiple-channels-in-v14-6-0/2779/5 "2021-09-30T09:01:15Z")

</div>

Hi Yeshwanth,  
I’m replying here in the same manner I’ve replied the (your?) support ticket:

This finding is caused by the xm.channel.webmaster userrole that is present on myproject-editors group. It gives editing rights (channel-webmaster permission) to all HST configurations, so making no distinction between HST configs of the French and English channels.

To get this straight, you’d have to split the xm.channel.webmaster role into webmaster roles per channel.

Haven’t tried it, but it looks like you need siblings of /hst:hst/hst:domains/hstconfig, granting editing rights to specific channel and channel-preview configurations.

HTH  
Jeroen
