Configure the Global Maximum Replacements Per Request
Current 10,000 default, hard request-wide ceiling across Rules, relation to per-Rule limits, preventing runaway replacements, and choosing conservative values.
This guide follows the accepted QC Dynamic Replacer 1.1.05 implementation and applies to All plans; settings managers. Where older manuals or walkthrough wording differs from the current source or the accepted keyless-entitlement behavior, the current implementation takes precedence.
Before You Begin
- Know how to disable Rule and Token Live Processing independently.
- Keep Administrator access available before testing broad or PHP-backed transformations.
- Check caches/CDNs when output varies by request, user, group, IP, or schedule.
Step-by-Step Workflow
- Identify whether the risk is Rule processing, Token processing, response size/replacement count, protected areas, or caching.
- Use the independent Live Processing controls or authorized bypass to preserve frontend access.
- Inspect the offending item in Administrator, which remains outside normal QCDR frontend transformation.
- Correct and privately test the item.
- Restore processing gradually and recheck caches/representative pages.
Current Runtime Safety Defaults
- Maximum HTML response size: 5 MB by default.
- Global maximum replacements per request: 10,000 by default.
- Per-Rule maximum replacements can narrow an individual Rule further; 0 means no additional per-Rule limit.
- Administrator, installer, and protected login/recovery contexts remain outside normal frontend transformation.
10,000 default
Runtime Safety provides request-wide bounds around transformation. The current defaults include a 5 MB maximum HTML response size and a 10,000-replacement hard ceiling per request; oversized or runaway work is skipped/limited instead of being allowed to grow without bound. QCDR also excludes Joomla Administrator and sensitive login/recovery/installer contexts from normal frontend transformation. An authorized one-request qcdr_bypass=1 path can help recover a broken frontend request, while the durable fix is to disable or correct the offending Rule/Token. Personalized Rule output must also be reconciled with Joomla/full-page/CDN caching so one visitor’s targeted variant is not reused for another.
For Configure the Global Maximum Replacements Per Request, evaluate this against the exact frontend request that matters. A saved QCDR item can be valid in Administrator yet remain inactive because a different eligibility gate, dependency, permission, cache layer, or runtime safety boundary correctly prevents transformation. Keeping those concerns separate makes both testing and later support much easier.
Hard request-wide ceiling across Rules
Runtime Safety provides request-wide bounds around transformation. The current defaults include a 5 MB maximum HTML response size and a 10,000-replacement hard ceiling per request; oversized or runaway work is skipped/limited instead of being allowed to grow without bound. QCDR also excludes Joomla Administrator and sensitive login/recovery/installer contexts from normal frontend transformation. An authorized one-request qcdr_bypass=1 path can help recover a broken frontend request, while the durable fix is to disable or correct the offending Rule/Token. Personalized Rule output must also be reconciled with Joomla/full-page/CDN caching so one visitor’s targeted variant is not reused for another.
For Configure the Global Maximum Replacements Per Request, evaluate this against the exact frontend request that matters. A saved QCDR item can be valid in Administrator yet remain inactive because a different eligibility gate, dependency, permission, cache layer, or runtime safety boundary correctly prevents transformation. Keeping those concerns separate makes both testing and later support much easier.
Relation to per-Rule limits
Runtime Safety provides request-wide bounds around transformation. The current defaults include a 5 MB maximum HTML response size and a 10,000-replacement hard ceiling per request; oversized or runaway work is skipped/limited instead of being allowed to grow without bound. QCDR also excludes Joomla Administrator and sensitive login/recovery/installer contexts from normal frontend transformation. An authorized one-request qcdr_bypass=1 path can help recover a broken frontend request, while the durable fix is to disable or correct the offending Rule/Token. Personalized Rule output must also be reconciled with Joomla/full-page/CDN caching so one visitor’s targeted variant is not reused for another.
Preventing runaway replacements
Runtime Safety provides request-wide bounds around transformation. The current defaults include a 5 MB maximum HTML response size and a 10,000-replacement hard ceiling per request; oversized or runaway work is skipped/limited instead of being allowed to grow without bound. QCDR also excludes Joomla Administrator and sensitive login/recovery/installer contexts from normal frontend transformation. An authorized one-request qcdr_bypass=1 path can help recover a broken frontend request, while the durable fix is to disable or correct the offending Rule/Token. Personalized Rule output must also be reconciled with Joomla/full-page/CDN caching so one visitor’s targeted variant is not reused for another.
And choosing conservative values
Runtime Safety provides request-wide bounds around transformation. The current defaults include a 5 MB maximum HTML response size and a 10,000-replacement hard ceiling per request; oversized or runaway work is skipped/limited instead of being allowed to grow without bound. QCDR also excludes Joomla Administrator and sensitive login/recovery/installer contexts from normal frontend transformation. An authorized one-request qcdr_bypass=1 path can help recover a broken frontend request, while the durable fix is to disable or correct the offending Rule/Token. Personalized Rule output must also be reconciled with Joomla/full-page/CDN caching so one visitor’s targeted variant is not reused for another.
How This Fits into QCDR
QCDR favors preserving original content when it cannot safely resolve a replacement. Runtime safety controls exist to prevent one bad Rule from becoming a site-wide outage.
The safest operating pattern is to keep configuration narrow, use QCDR’s private diagnostics before broad activation when your tier permits them, and preserve Joomla Administrator as the recovery surface. Because QCDR changes the rendered response rather than source files, a correctly disabled or bypassed runtime path should expose the underlying Joomla output again without requiring a source-file rollback.
Verify the Result
- The Rule state and drag order are exactly what you intended.
- A page that should match changes as expected, and a page outside scope remains unchanged.
- Reload the real frontend request instead of relying only on the saved Administrator form.
- Check Joomla/CDN cache effects if the result is request-specific.
Common Mistakes to Avoid
- Changing several gates at once during troubleshooting, which makes the actual cause difficult to identify.
- Testing only while signed in as Super User when ordinary users/guests are the intended audience.
- Skipping a recovery plan before enabling a site-wide HTML, JavaScript, protected-area, or PHP-backed change.
Troubleshooting
- If nothing changes, confirm the package-owned System plugin is enabled, the relevant Live Processing switch is on, and the item is eligible for the current Effective tier.
- If targeting appears wrong, inspect page/menu/URL, extension, audience, schedule, IP, technical conditions, and protected-region behavior as separate gates.
- If a Token-backed Rule preserves the original match, troubleshoot the Token dependency/readiness before changing the Find value.
- If behavior differs between browsers/users, clear or bypass relevant Joomla/full-page/CDN caches and compare request context.
- If private Preview/Discovery fails, start a fresh authorized same-site session and confirm the Joomla ACL action as well as the product tier.
Operational Best Practice
Make runtime changes deliberately: use a narrow scope first, keep broad Rules Draft or Disabled until tested, preserve the independent Rule/Token emergency switches, and record the QCDR version plus the exact Rule/Token and affected URL when handing a problem to another administrator. For high-impact HTML, protected-region, JavaScript, dynamic-data, or PHP work, test representative anonymous and authenticated requests and review caching before expanding scope.
Community Discussion
Want to compare workflows, share practical examples, or discuss how other administrators use this QCDR feature? Visit the QC Dynamic Replacer Community. For private support, bug reports, account-specific entitlement problems, or feature requests, use the QuantaCade support system.