Activate Restricted Assets Access to Dynamic Media with Open APIs based on IMS User Groups
This article explains how to activate the restricted access to Dynamic Media in ÃÛ¶¹ÊÓÆµ Experience Manager Assets using Open APIs based on IMS user groups. According to the documentation, this feature needs to be activated first.
Description description
Environments
- ÃÛ¶¹ÊÓÆµ Experience Manager as a Cloud Service (AEMaaCS) - Assets
- Dynamic Media (DM)
Issue/Symptoms
Enable the feature that restricts access to approved assets based on IMS user groups. According to the documentation, this feature needs to be activated first.
Resolution resolution
Prerequisites
- Ensure you have AEMaaCS Assets with the Dynamic Media add-on licensed.
- Then, submit a Customer Care ticket to set up DM with Open APIs if not done yet.
Controlling Delivery URLs
- Restrictions on delivery URLs can be controlled through a metadata property
dam:roles
at the asset level. IMS IDs of users/groups can be added todam:roles
. - When a delivery URL is accessed, a user token must be provided in the request. The request will be fulfilled if the user is allowed at
dam:roles
or is part of an allowed group.
Adding dam:roles
to Assets
dam:roles
can be added via the UI or using the Metadata Profile feature to auto-adddam:roles
to all assets uploaded inside a folder.
Setting Up Metadata Schema
- To allow authors to see/edit the metadata property, a metadata schema should be set up and applied to the folders where restricted assets are served from.
3d58f420-19b5-47a0-a122-5c9dab55ec7f