Legacy Knowledge Base
Published Sep. 10, 2025

Controlling Role Visibility via Headless API

Written By

Jorge Diaz

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

Legacy Article

You are viewing an article from our legacy "FastTrack" publication program, made available for informational purposes. Articles in this program were published without a requirement for independent editing or verification and are provided"as is" without guarantee.

Before using any information from this article, independently verify its suitability for your situation and project.

Issue

  • The /o/headless-admin-user/v1.0/roles API exposes all system roles, potentially revealing sensitive information about permission structures, user roles, and their associated components (portlets).

Environment

  • Liferay DXP 7.4
  • Liferay DXP Quarterly Releases

Resolution

  • You can control the role visibility through the API by managing each role's permissions. By default:
    • Owner: All permissions.
    • User (authenticated users): View permission.
    • Guest (anonymous users): No view permission.
  • To restrict a specific role's visibility (e.g., Administrator):
    1. Go to the role (e.g., Administrator).
    2. In the options menu (), select Permissions.
    3. Remove the View permission from the User role. 
  • This prevents non-administrative users from seeing the "Administrator" role via the API.
  • Nevertheless, if an attacker knows a system uses Liferay, they don't need to access its API to find default permissions and portlets. This is because Liferay is open-source, allowing access to its code, and the software can be downloaded and installed locally to inspect its default settings.

Additional Information

 

 

 

Did this article resolve your issue ?

Legacy Knowledge Base