How do I get information about the current user with GraphQL?
Question
How do I get information about the current user with GraphQL?
Answer
Use the currentUser field on the root query. It returns the user bound to the
current session.
{
currentUser {
username
displayName
email
firstname
lastname
language
locked
organization
}
}
On a default instance, authenticated as root:
{
"data": {
"currentUser": {
"username": "root",
"displayName": "root",
"email": null,
"firstname": null,
"lastname": null,
"language": "en",
"locked": false,
"organization": null
}
}
}
A property that is not set comes back as null rather than being omitted.
Fields that take arguments
{
currentUser {
property(name: "j:firstName")
memberOf(group: "administrators")
node { uuid path primaryNodeType { name } }
site { displayName }
}
}
property(name: String)reads any user property that has no dedicated field.memberOf(group: String, site: String)returns a boolean. Omitsitefor a server-level group.nodeis the underlyingjnt:userJCR node, for example/users/root. Use it when you need something thecurrentUsertype does not expose directly.siteis the site the user is defined in.
"My front end gets the guest user back from currentUser"
It does not. This is worth stating plainly because it is a common assumption and it sends people looking in the wrong place.
Jahia does have a guest user, and server-side rendering does distinguish it
from a logged-in user - that is what renderContext.loggedIn is for in a JSP
view. None of that applies to this GraphQL field. currentUser does not fall
back to guest for an anonymous caller; it returns an error instead, as below. If
you are reading advice about guest users and renderContext, you are reading
about template rendering, not about this API.
For an anonymous front end calling GraphQL, "not logged in" is signalled by a
GqlAccessDeniedException on currentUser, not by a user named guest.
It requires authentication
Calling currentUser without credentials does not return a guest user. It
fails:
{
"errors": [{
"message": "Permission denied",
"extensions": { "classification": "GqlAccessDeniedException" }
}],
"data": { "currentUser": null }
}
So a front end that may be anonymous has to handle that error rather than expect
a guest user back. Check for authentication before issuing the query, or treat
GqlAccessDeniedException on this field as "not logged in".
This article was drafted with AI assistance, then reviewed and curated by Jahia Customer Support engineers before publication.