Control Who Can Access the QCDR Frontend Workspace
qc_dynamic_replacer.use_workspace permission, guest sign-in response, access denied behavior, menu access considerations, and least-privilege setup.
This guide follows the accepted QC Dynamic Replacer 1.1.05 implementation and applies to All plans; Joomla ACL administrator. Where older manuals or walkthrough wording differs from the current source or the accepted keyless-entitlement behavior, the current implementation takes precedence.
Before You Begin
- Plan least-privilege groups before assigning specialized QCDR actions.
- Remember that entitlement and Joomla permission are separate gates.
- Test with a non-Super-User account after ACL changes.
Step-by-Step Workflow
- Identify the minimum QCDR action the user/group needs.
- Configure Joomla ACL without granting unrelated entitlement/settings/code privileges.
- Test with the delegated account rather than the Super User session.
- Verify denial behavior for actions that should remain restricted.
- Document the assigned group/action for later audits.
QCDR Joomla Permission Reference
| Action | What it controls |
|---|---|
| core.manage / core.admin | Baseline Administrator component access/inheritance. |
| Manage Settings | Change installation-wide QCDR settings. |
| Manage License | Use entitlement/license-management actions. |
| Manage Rules | Create and maintain Rules. |
| Manage Tokens | Create and maintain non-PHP Tokens. |
| Manage PHP Tokens | Independently author/modify PHP Tokens; required in addition to Max/All Access. |
| Test Rules | Launch authorized private Preview and Rule Health. |
| Run Discovery | Launch private Discovery / Click It, Change It sessions and Draft Rule handoff. |
| Use Workspace | Open the frontend Dynamic Replacer Workspace readiness dashboard. |
Qc_dynamic_replacer.use_workspace permission
QCDR targeting narrows runtime eligibility before replacement occurs. Basic can scope by frontend pages/menu items and URL/path patterns. Pro adds component or supported site-module boundaries and audience targeting for guests, authenticated users, or selected Joomla groups. Targeting is evaluated against the actual request context, so a Rule can be correctly configured yet inactive on a page that does not match every selected gate. Personalized output also requires cache planning so a full-page or CDN cache does not serve one audience variant to another visitor.
For Control Who Can Access the QCDR Frontend Workspace, evaluate this against the exact frontend request that matters. A saved QCDR item can be valid in Administrator yet remain inactive because a different eligibility gate, dependency, permission, cache layer, or runtime safety boundary correctly prevents transformation. Keeping those concerns separate makes both testing and later support much easier.
Guest sign-in response
QCDR targeting narrows runtime eligibility before replacement occurs. Basic can scope by frontend pages/menu items and URL/path patterns. Pro adds component or supported site-module boundaries and audience targeting for guests, authenticated users, or selected Joomla groups. Targeting is evaluated against the actual request context, so a Rule can be correctly configured yet inactive on a page that does not match every selected gate. Personalized output also requires cache planning so a full-page or CDN cache does not serve one audience variant to another visitor.
For Control Who Can Access the QCDR Frontend Workspace, evaluate this against the exact frontend request that matters. A saved QCDR item can be valid in Administrator yet remain inactive because a different eligibility gate, dependency, permission, cache layer, or runtime safety boundary correctly prevents transformation. Keeping those concerns separate makes both testing and later support much easier.
Access denied behavior
QCDR targeting narrows runtime eligibility before replacement occurs. Basic can scope by frontend pages/menu items and URL/path patterns. Pro adds component or supported site-module boundaries and audience targeting for guests, authenticated users, or selected Joomla groups. Targeting is evaluated against the actual request context, so a Rule can be correctly configured yet inactive on a page that does not match every selected gate. Personalized output also requires cache planning so a full-page or CDN cache does not serve one audience variant to another visitor.
Menu access considerations
QCDR targeting narrows runtime eligibility before replacement occurs. Basic can scope by frontend pages/menu items and URL/path patterns. Pro adds component or supported site-module boundaries and audience targeting for guests, authenticated users, or selected Joomla groups. Targeting is evaluated against the actual request context, so a Rule can be correctly configured yet inactive on a page that does not match every selected gate. Personalized output also requires cache planning so a full-page or CDN cache does not serve one audience variant to another visitor.
And least-privilege setup
QCDR targeting narrows runtime eligibility before replacement occurs. Basic can scope by frontend pages/menu items and URL/path patterns. Pro adds component or supported site-module boundaries and audience targeting for guests, authenticated users, or selected Joomla groups. Targeting is evaluated against the actual request context, so a Rule can be correctly configured yet inactive on a page that does not match every selected gate. Personalized output also requires cache planning so a full-page or CDN cache does not serve one audience variant to another visitor.
How This Fits into QCDR
The frontend Workspace is a readiness/status surface. Rule and Token editing remains an Administrator workflow.
The safest operating pattern is to keep configuration narrow, use QCDR’s private diagnostics before broad activation when your tier permits them, and preserve Joomla Administrator as the recovery surface. Because QCDR changes the rendered response rather than source files, a correctly disabled or bypassed runtime path should expose the underlying Joomla output again without requiring a source-file rollback.
Verify the Result
- The delegated user can perform only the intended QCDR actions.
- The same user is denied actions that were intentionally withheld.
- Reload the real frontend request instead of relying only on the saved Administrator form.
- Check Joomla/CDN cache effects if the result is request-specific.
Common Mistakes to Avoid
- Changing several gates at once during troubleshooting, which makes the actual cause difficult to identify.
- Testing only while signed in as Super User when ordinary users/guests are the intended audience.
- Skipping a recovery plan before enabling a site-wide HTML, JavaScript, protected-area, or PHP-backed change.
Troubleshooting
- If nothing changes, confirm the package-owned System plugin is enabled, the relevant Live Processing switch is on, and the item is eligible for the current Effective tier.
- If targeting appears wrong, inspect page/menu/URL, extension, audience, schedule, IP, technical conditions, and protected-region behavior as separate gates.
- If a Token-backed Rule preserves the original match, troubleshoot the Token dependency/readiness before changing the Find value.
- If behavior differs between browsers/users, clear or bypass relevant Joomla/full-page/CDN caches and compare request context.
- If private Preview/Discovery fails, start a fresh authorized same-site session and confirm the Joomla ACL action as well as the product tier.
Operational Best Practice
Make runtime changes deliberately: use a narrow scope first, keep broad Rules Draft or Disabled until tested, preserve the independent Rule/Token emergency switches, and record the QCDR version plus the exact Rule/Token and affected URL when handing a problem to another administrator. For high-impact HTML, protected-region, JavaScript, dynamic-data, or PHP work, test representative anonymous and authenticated requests and review caching before expanding scope.
Community Discussion
Want to compare workflows, share practical examples, or discuss how other administrators use this QCDR feature? Visit the QC Dynamic Replacer Community. For private support, bug reports, account-specific entitlement problems, or feature requests, use the QuantaCade support system.