QCDR Technical Condition Operators and All-vs-Any Logic
equals/not_equals/contains/not_contains/starts_with/ends_with/matches/in/not_in behavior, comma lists, query key=value handling, and AND/OR logic.
This guide follows the accepted QC Dynamic Replacer 1.1.05 implementation and applies to Max / All Access; rule/token managers. Where older manuals or walkthrough wording differs from the current source or the accepted keyless-entitlement behavior, the current implementation takes precedence.
Before You Begin
- Start with the narrowest page scope that proves the use case.
- Account for Joomla caching/CDN behavior before relying on audience or IP-specific output.
- Use Preview/Rule Health for complicated gate combinations whenever available.
Step-by-Step Workflow
- Open the Rule or Token and identify its current broad scope.
- Add the narrowest targeting gate required for the use case.
- Save and test both a request that should pass and one that should fail.
- Use Rule Health for layered gate diagnosis when available.
- Review caches when the target varies by visitor or request context.
Condition Vocabulary
Current technical conditions can inspect URL, menu, component, view, language, user group, template, hostname, query, request method.
Supported comparison operators include equals, not_equals, contains, not_contains, starts_with, ends_with, matches, in, not_in. Use All logic when every condition must pass, or Any logic when one passing condition is sufficient.
Equals/not_equals/contains/not_contains/starts_with/ends_with/matches/in/not_i
Max technical targeting adds IP include/exclude rules and request/Joomla-context conditions. IP entries can use IPv4/IPv6 addresses, ranges, or CIDR. Forwarded client-IP headers should be trusted only when the immediate proxy/load balancer is explicitly listed in the Trusted proxy addresses/CIDR setting; otherwise a visitor-controlled header could become a spoofing path. Technical conditions can evaluate URL, menu, component, view, language, user group, template, hostname, query, and request method with the supported comparison operators and All/Any logic. Protected script/style/code-like regions are skipped by default; allowing processing there is an explicit Max opt-in that deserves Preview-first testing.
For QCDR Technical Condition Operators and All-vs-Any Logic, evaluate this against the exact frontend request that matters. A saved QCDR item can be valid in Administrator yet remain inactive because a different eligibility gate, dependency, permission, cache layer, or runtime safety boundary correctly prevents transformation. Keeping those concerns separate makes both testing and later support much easier.
Comma lists
Max technical targeting adds IP include/exclude rules and request/Joomla-context conditions. IP entries can use IPv4/IPv6 addresses, ranges, or CIDR. Forwarded client-IP headers should be trusted only when the immediate proxy/load balancer is explicitly listed in the Trusted proxy addresses/CIDR setting; otherwise a visitor-controlled header could become a spoofing path. Technical conditions can evaluate URL, menu, component, view, language, user group, template, hostname, query, and request method with the supported comparison operators and All/Any logic. Protected script/style/code-like regions are skipped by default; allowing processing there is an explicit Max opt-in that deserves Preview-first testing.
For QCDR Technical Condition Operators and All-vs-Any Logic, evaluate this against the exact frontend request that matters. A saved QCDR item can be valid in Administrator yet remain inactive because a different eligibility gate, dependency, permission, cache layer, or runtime safety boundary correctly prevents transformation. Keeping those concerns separate makes both testing and later support much easier.
Query key=value handling
Max technical targeting adds IP include/exclude rules and request/Joomla-context conditions. IP entries can use IPv4/IPv6 addresses, ranges, or CIDR. Forwarded client-IP headers should be trusted only when the immediate proxy/load balancer is explicitly listed in the Trusted proxy addresses/CIDR setting; otherwise a visitor-controlled header could become a spoofing path. Technical conditions can evaluate URL, menu, component, view, language, user group, template, hostname, query, and request method with the supported comparison operators and All/Any logic. Protected script/style/code-like regions are skipped by default; allowing processing there is an explicit Max opt-in that deserves Preview-first testing.
And AND/OR logic
Max technical targeting adds IP include/exclude rules and request/Joomla-context conditions. IP entries can use IPv4/IPv6 addresses, ranges, or CIDR. Forwarded client-IP headers should be trusted only when the immediate proxy/load balancer is explicitly listed in the Trusted proxy addresses/CIDR setting; otherwise a visitor-controlled header could become a spoofing path. Technical conditions can evaluate URL, menu, component, view, language, user group, template, hostname, query, and request method with the supported comparison operators and All/Any logic. Protected script/style/code-like regions are skipped by default; allowing processing there is an explicit Max opt-in that deserves Preview-first testing.
How This Fits into QCDR
Targeting gates stack. A Rule or Token must pass every required gate in its current tier before it is eligible.
The safest operating pattern is to keep configuration narrow, use QCDR’s private diagnostics before broad activation when your tier permits them, and preserve Joomla Administrator as the recovery surface. Because QCDR changes the rendered response rather than source files, a correctly disabled or bypassed runtime path should expose the underlying Joomla output again without requiring a source-file rollback.
Verify the Result
- Reload the real frontend request instead of relying only on the saved Administrator form.
- Check Joomla/CDN cache effects if the result is request-specific.
Common Mistakes to Avoid
- Changing several gates at once during troubleshooting, which makes the actual cause difficult to identify.
- Testing only while signed in as Super User when ordinary users/guests are the intended audience.
- Skipping a recovery plan before enabling a site-wide HTML, JavaScript, protected-area, or PHP-backed change.
Troubleshooting
- If nothing changes, confirm the package-owned System plugin is enabled, the relevant Live Processing switch is on, and the item is eligible for the current Effective tier.
- If targeting appears wrong, inspect page/menu/URL, extension, audience, schedule, IP, technical conditions, and protected-region behavior as separate gates.
- If a Token-backed Rule preserves the original match, troubleshoot the Token dependency/readiness before changing the Find value.
- If behavior differs between browsers/users, clear or bypass relevant Joomla/full-page/CDN caches and compare request context.
- If private Preview/Discovery fails, start a fresh authorized same-site session and confirm the Joomla ACL action as well as the product tier.
Operational Best Practice
Make runtime changes deliberately: use a narrow scope first, keep broad Rules Draft or Disabled until tested, preserve the independent Rule/Token emergency switches, and record the QCDR version plus the exact Rule/Token and affected URL when handing a problem to another administrator. For high-impact HTML, protected-region, JavaScript, dynamic-data, or PHP work, test representative anonymous and authenticated requests and review caching before expanding scope.
Community Discussion
Want to compare workflows, share practical examples, or discuss how other administrators use this QCDR feature? Visit the QC Dynamic Replacer Community. For private support, bug reports, account-specific entitlement problems, or feature requests, use the QuantaCade support system.