How QCDR Private Preview Authorization Protects Test Requests
Signed short-lived authorization, Super User/Test Rules gate, same-site URL enforcement, no-store/no-cache/noindex response behavior, and fail-closed expiry.
This guide follows the accepted QC Dynamic Replacer 1.1.05 implementation and applies to Pro / Max / All Access; administrators. Where older manuals or walkthrough wording differs from the current source or the accepted keyless-entitlement behavior, the current implementation takes precedence.
Before You Begin
- Save the Rule first; Preview/Rule Health works from a saved Rule identity.
- Use only a same-site frontend URL.
- Keep the private test authorization fresh and do not mistake a Preview result for ordinary visitor state.
Step-by-Step Workflow
- Save the Rule first, even if it remains Draft or Disabled.
- Confirm your Joomla account has Test Rules and the current tier includes private Preview.
- Enter a same-site frontend URL that represents the intended Rule target.
- Launch Preview from the Rule editor and inspect the private transformed page.
- Read Rule Health for state/tier, target, audience, schedule, dependency, match, and protected-region gates.
- Correct the Rule and relaunch Preview rather than enabling it just to test.
- After successful private testing, enable the Rule only if ordinary runtime behavior is desired.
Signed short-lived authorization
Pro/Max private Preview tests a saved Rule against a real same-site frontend request using short-lived signed authorization. A saved Draft or Disabled Rule can be exercised without changing ordinary visitor state, and test responses are treated as private/no-store contexts. Rule Health reports the gates that determine eligibility—state/tier, page/menu/extension, audience, schedule, IP, technical conditions, Token readiness, match/replacement readiness, protected regions, and final result. Discovery-created target fingerprints add advisory drift evidence; even a strong likely candidate is never silently adopted as a new Rule target.
For How QCDR Private Preview Authorization Protects Test Requests, evaluate this against the exact frontend request that matters. A saved QCDR item can be valid in Administrator yet remain inactive because a different eligibility gate, dependency, permission, cache layer, or runtime safety boundary correctly prevents transformation. Keeping those concerns separate makes both testing and later support much easier.
Super User/Test Rules gate
Pro/Max private Preview tests a saved Rule against a real same-site frontend request using short-lived signed authorization. A saved Draft or Disabled Rule can be exercised without changing ordinary visitor state, and test responses are treated as private/no-store contexts. Rule Health reports the gates that determine eligibility—state/tier, page/menu/extension, audience, schedule, IP, technical conditions, Token readiness, match/replacement readiness, protected regions, and final result. Discovery-created target fingerprints add advisory drift evidence; even a strong likely candidate is never silently adopted as a new Rule target.
For How QCDR Private Preview Authorization Protects Test Requests, evaluate this against the exact frontend request that matters. A saved QCDR item can be valid in Administrator yet remain inactive because a different eligibility gate, dependency, permission, cache layer, or runtime safety boundary correctly prevents transformation. Keeping those concerns separate makes both testing and later support much easier.
Same-site URL enforcement
Pro/Max private Preview tests a saved Rule against a real same-site frontend request using short-lived signed authorization. A saved Draft or Disabled Rule can be exercised without changing ordinary visitor state, and test responses are treated as private/no-store contexts. Rule Health reports the gates that determine eligibility—state/tier, page/menu/extension, audience, schedule, IP, technical conditions, Token readiness, match/replacement readiness, protected regions, and final result. Discovery-created target fingerprints add advisory drift evidence; even a strong likely candidate is never silently adopted as a new Rule target.
No-store/no-cache/noindex response behavior
Pro/Max private Preview tests a saved Rule against a real same-site frontend request using short-lived signed authorization. A saved Draft or Disabled Rule can be exercised without changing ordinary visitor state, and test responses are treated as private/no-store contexts. Rule Health reports the gates that determine eligibility—state/tier, page/menu/extension, audience, schedule, IP, technical conditions, Token readiness, match/replacement readiness, protected regions, and final result. Discovery-created target fingerprints add advisory drift evidence; even a strong likely candidate is never silently adopted as a new Rule target.
And fail-closed expiry
Pro/Max private Preview tests a saved Rule against a real same-site frontend request using short-lived signed authorization. A saved Draft or Disabled Rule can be exercised without changing ordinary visitor state, and test responses are treated as private/no-store contexts. Rule Health reports the gates that determine eligibility—state/tier, page/menu/extension, audience, schedule, IP, technical conditions, Token readiness, match/replacement readiness, protected regions, and final result. Discovery-created target fingerprints add advisory drift evidence; even a strong likely candidate is never silently adopted as a new Rule target.
How This Fits into QCDR
Preview and Rule Health are private diagnostics. They do not need to enable the Rule for ordinary visitors.
The safest operating pattern is to keep configuration narrow, use QCDR’s private diagnostics before broad activation when your tier permits them, and preserve Joomla Administrator as the recovery surface. Because QCDR changes the rendered response rather than source files, a correctly disabled or bypassed runtime path should expose the underlying Joomla output again without requiring a source-file rollback.
Verify the Result
- Status shows the expected Base and Effective tiers for the normalized domain.
- Entitlement Revalidation is healthy and hourly unless the article is specifically diagnosing that task.
- The Rule state and drag order are exactly what you intended.
- A page that should match changes as expected, and a page outside scope remains unchanged.
- Reload the real frontend request instead of relying only on the saved Administrator form.
- Check Joomla/CDN cache effects if the result is request-specific.
Common Mistakes to Avoid
- Enabling a broad Rule for ordinary visitors merely to test something private Preview can validate safely.
- Testing personalized output through a shared page/CDN cache and assuming the cached result reflects current eligibility.
- Changing several gates at once during troubleshooting, which makes the actual cause difficult to identify.
- Testing only while signed in as Super User when ordinary users/guests are the intended audience.
- Skipping a recovery plan before enabling a site-wide HTML, JavaScript, protected-area, or PHP-backed change.
Troubleshooting
- If nothing changes, confirm the package-owned System plugin is enabled, the relevant Live Processing switch is on, and the item is eligible for the current Effective tier.
- If targeting appears wrong, inspect page/menu/URL, extension, audience, schedule, IP, technical conditions, and protected-region behavior as separate gates.
- If a Token-backed Rule preserves the original match, troubleshoot the Token dependency/readiness before changing the Find value.
- If behavior differs between browsers/users, clear or bypass relevant Joomla/full-page/CDN caches and compare request context.
- If private Preview/Discovery fails, start a fresh authorized same-site session and confirm the Joomla ACL action as well as the product tier.
Operational Best Practice
Make runtime changes deliberately: use a narrow scope first, keep broad Rules Draft or Disabled until tested, preserve the independent Rule/Token emergency switches, and record the QCDR version plus the exact Rule/Token and affected URL when handing a problem to another administrator. For high-impact HTML, protected-region, JavaScript, dynamic-data, or PHP work, test representative anonymous and authenticated requests and review caching before expanding scope.
Community Discussion
Want to compare workflows, share practical examples, or discuss how other administrators use this QCDR feature? Visit the QC Dynamic Replacer Community. For private support, bug reports, account-specific entitlement problems, or feature requests, use the QuantaCade support system.