Troubleshoot QCDR Discovery Sessions and Impact Scans

Tier/ACL/auth expiry, blocked URL classes, same-site origin, missing evidence, LIKELY vs EXACT expectations, scan limits, late DOM timing, and session restart.

This guide follows the accepted QC Dynamic Replacer 1.1.05 implementation and applies to Max / All Access; administrators. Where older manuals or walkthrough wording differs from the current source or the accepted keyless-entitlement behavior, the current implementation takes precedence.

Before You Begin

  • Discovery is private and same-origin; open it from the authorized Administrator workflow.
  • Treat evidence/confidence as guidance, not as permission for automatic retargeting.
  • Use bounded scans and close/restart sessions when authorization expires.

Step-by-Step Workflow

  1. Confirm Effective Max/All Access and the Run Discovery permission.
  2. Open Discovery from QCDR Administrator and enter a safe same-site frontend URL.
  3. Launch a fresh private session; do not reuse an expired authorization.
  4. Select output, search for a phrase, or run the bounded analysis tool relevant to the question.
  5. Review evidence, confidence, render context, Rule effects, and any captured fingerprint.
  6. If appropriate, prepare a Draft Rule from the finding; review its scope and replacement before saving.
  7. Exit Discovery and verify the eventual Rule independently before enabling it for ordinary visitors.

Discovery Tool Reference

ToolPurpose
Click It, Change ItSelect rendered output privately and inspect evidence before creating a Draft Rule.
Page ScanBounded inventory of notable text/headings, links/buttons, media, forms, Token regions, component/module markers, and Rule effects.
Explain This OutputMove a Page Scan result into the standard evidence/fingerprint inspector.
Site Impact ScanCheck the current page, published menu routes, and supplied same-site URLs; current limit is 40 de-duplicated pages.
Dynamic DOM WatchObserve late browser-side DOM mutation for up to 60 seconds or 600 mutation records; timing is evidence, not JavaScript call-stack attribution.

QCDR Joomla Permission Reference

ActionWhat it controls
core.manage / core.adminBaseline Administrator component access/inheritance.
Manage SettingsChange installation-wide QCDR settings.
Manage LicenseUse entitlement/license-management actions.
Manage RulesCreate and maintain Rules.
Manage TokensCreate and maintain non-PHP Tokens.
Manage PHP TokensIndependently author/modify PHP Tokens; required in addition to Max/All Access.
Test RulesLaunch authorized private Preview and Rule Health.
Run DiscoveryLaunch private Discovery / Click It, Change It sessions and Draft Rule handoff.
Use WorkspaceOpen the frontend Dynamic Replacer Workspace readiness dashboard.

Tier/ACL/auth expiry

Current new-Rule Find choices focus on rendered output: Anything/detect automatically, Text, HTML, CSS, JavaScript, PHP-like rendered source, and URL or image/media references. Matching can be exact/whole-term or partial, optionally case-sensitive, and can target All, First, Last, or a Specific occurrence. A per-Rule maximum can further bound replacements; 0 means no additional Rule-specific cap, while the global request ceiling in Settings still applies. Retired JSON/XML/INI Find choices and Count Only are not current new-Rule workflows.

For Troubleshoot QCDR Discovery Sessions and Impact Scans, evaluate this against the exact frontend request that matters. A saved QCDR item can be valid in Administrator yet remain inactive because a different eligibility gate, dependency, permission, cache layer, or runtime safety boundary correctly prevents transformation. Keeping those concerns separate makes both testing and later support much easier.

Blocked URL classes

Current new-Rule Find choices focus on rendered output: Anything/detect automatically, Text, HTML, CSS, JavaScript, PHP-like rendered source, and URL or image/media references. Matching can be exact/whole-term or partial, optionally case-sensitive, and can target All, First, Last, or a Specific occurrence. A per-Rule maximum can further bound replacements; 0 means no additional Rule-specific cap, while the global request ceiling in Settings still applies. Retired JSON/XML/INI Find choices and Count Only are not current new-Rule workflows.

For Troubleshoot QCDR Discovery Sessions and Impact Scans, evaluate this against the exact frontend request that matters. A saved QCDR item can be valid in Administrator yet remain inactive because a different eligibility gate, dependency, permission, cache layer, or runtime safety boundary correctly prevents transformation. Keeping those concerns separate makes both testing and later support much easier.

Same-site origin

Current new-Rule Find choices focus on rendered output: Anything/detect automatically, Text, HTML, CSS, JavaScript, PHP-like rendered source, and URL or image/media references. Matching can be exact/whole-term or partial, optionally case-sensitive, and can target All, First, Last, or a Specific occurrence. A per-Rule maximum can further bound replacements; 0 means no additional Rule-specific cap, while the global request ceiling in Settings still applies. Retired JSON/XML/INI Find choices and Count Only are not current new-Rule workflows.

Missing evidence

Current new-Rule Find choices focus on rendered output: Anything/detect automatically, Text, HTML, CSS, JavaScript, PHP-like rendered source, and URL or image/media references. Matching can be exact/whole-term or partial, optionally case-sensitive, and can target All, First, Last, or a Specific occurrence. A per-Rule maximum can further bound replacements; 0 means no additional Rule-specific cap, while the global request ceiling in Settings still applies. Retired JSON/XML/INI Find choices and Count Only are not current new-Rule workflows.

LIKELY vs EXACT expectations

Current new-Rule Find choices focus on rendered output: Anything/detect automatically, Text, HTML, CSS, JavaScript, PHP-like rendered source, and URL or image/media references. Matching can be exact/whole-term or partial, optionally case-sensitive, and can target All, First, Last, or a Specific occurrence. A per-Rule maximum can further bound replacements; 0 means no additional Rule-specific cap, while the global request ceiling in Settings still applies. Retired JSON/XML/INI Find choices and Count Only are not current new-Rule workflows.

How This Fits into QCDR

Discovery is intentionally non-mutating until you deliberately carry a finding into a Draft Rule and review/save it.

The safest operating pattern is to keep configuration narrow, use QCDR’s private diagnostics before broad activation when your tier permits them, and preserve Joomla Administrator as the recovery surface. Because QCDR changes the rendered response rather than source files, a correctly disabled or bypassed runtime path should expose the underlying Joomla output again without requiring a source-file rollback.

Verify the Result

  • The Discovery session remains private/same-site and no Rule was silently enabled or retargeted.
  • Any Draft Rule created from evidence was manually reviewed before use.
  • The delegated user can perform only the intended QCDR actions.
  • The same user is denied actions that were intentionally withheld.
  • Reload the real frontend request instead of relying only on the saved Administrator form.
  • Check Joomla/CDN cache effects if the result is request-specific.

Common Mistakes to Avoid

  • Treating LIKELY/LOW/MEDIUM evidence as automatic authority to retarget or enable a Rule.
  • Changing several gates at once during troubleshooting, which makes the actual cause difficult to identify.
  • Testing only while signed in as Super User when ordinary users/guests are the intended audience.
  • Skipping a recovery plan before enabling a site-wide HTML, JavaScript, protected-area, or PHP-backed change.

Troubleshooting

  • If nothing changes, confirm the package-owned System plugin is enabled, the relevant Live Processing switch is on, and the item is eligible for the current Effective tier.
  • If targeting appears wrong, inspect page/menu/URL, extension, audience, schedule, IP, technical conditions, and protected-region behavior as separate gates.
  • If a Token-backed Rule preserves the original match, troubleshoot the Token dependency/readiness before changing the Find value.
  • If behavior differs between browsers/users, clear or bypass relevant Joomla/full-page/CDN caches and compare request context.
  • If private Preview/Discovery fails, start a fresh authorized same-site session and confirm the Joomla ACL action as well as the product tier.

Operational Best Practice

Make runtime changes deliberately: use a narrow scope first, keep broad Rules Draft or Disabled until tested, preserve the independent Rule/Token emergency switches, and record the QCDR version plus the exact Rule/Token and affected URL when handing a problem to another administrator. For high-impact HTML, protected-region, JavaScript, dynamic-data, or PHP work, test representative anonymous and authenticated requests and review caching before expanding scope.


Community Discussion

Want to compare workflows, share practical examples, or discuss how other administrators use this QCDR feature? Visit the QC Dynamic Replacer Community. For private support, bug reports, account-specific entitlement problems, or feature requests, use the QuantaCade support system.