Authorized Domains and Keyless QCMM Entitlement

Explain current Authorized-Domain entitlement, where the domain is managed, how QCMM resolves paid access, and why current releases do not require customers to paste a license key into Joomla.

This guide follows the accepted QC Memberships & Meetings 2.0.21 implementation and applies to All plans; administrator. This category establishes installation, entitlement, administrator navigation, permissions, update safety, and the first end-to-end membership test that every other QCMM workflow depends on. When older walkthrough or project-manual wording conflicts with 2.0.21 source or later accepted Authorized-Domain behavior, the current implementation takes precedence.

Before You Begin

  • Take a current Joomla/site backup before installing, upgrading, changing component permissions, or making entitlement-related repairs.
  • Confirm you can access Joomla Administrator, Extensions, Scheduled Tasks, and the frontend login/menu areas used by QCMM.
  • Record the installed QCMM version plus the current Base tier and Effective tier before changing entitlement or task state.

Current QCMM Behavior

ItemCurrent behavior
Current versionQC Memberships & Meetings 2.0.21
Current licensingKeyless Authorized-Domain entitlement
PreviewOne-time 30-Day Max Preview; explicit administrator start only
Canonical entitlement taskEntitlement Revalidation every 60 minutes
Administrator tabsAbout, Support, Status, Settings, Plans, Scheduling, Promotions, Subscriptions, Member Area, Email, Billing, Reports, CSS

Step-by-Step Workflow

  1. Open QCMM Status and read the current domain, Base tier, Effective tier, entitlement dates, verification mode, and task health.
  2. Use Authorized Domains in the QuantaCade account when paid access is expected; do not paste a new customer license key into Joomla.
  3. Use only the intended administrator action: refresh current entitlement, clear legacy saved-key state, or explicitly start the one-time 30-Day Max Preview.
  4. Reopen Status and verify Base and Effective tier remain distinct and preview dates are not reset.
  5. Confirm the Entitlement Revalidation Scheduled Task is canonical at 60 minutes when above-Basic access is expected.

Authorized Domains and Keyless QCMM Entitlement

Explain current Authorized-Domain entitlement, where the domain is managed, how QCMM resolves paid access, and why current releases do not require customers to paste a license key into Joomla is part of the current QCMM 2.0.21 behavior. Treat the stored QCMM record and server-side authorization as authoritative: frontend controls guide the user, but QCMM still validates identity, ownership/access, current object state, entitlement, and request integrity when an action is submitted.

Keep responsibilities clear: Joomla remains authoritative for users, sessions, access levels, groups, mail transport, and Scheduled Tasks; QCMM owns membership, billing, scheduling, Meeting, Custom Field, resource, and related frontend state. This separation is useful both for security and for troubleshooting.

Current Details That Matter

  • Current paid access is resolved from Authorized Domains; a customer-entered current license key is not part of the 2.0.21 activation workflow.
  • Normal frontend rendering uses local signed entitlement state and task-health checks; it does not perform remote entitlement HTTP calls or migration writes.

How This Fits into QC Memberships & Meetings

This category establishes installation, entitlement, administrator navigation, permissions, update safety, and the first end-to-end membership test that every other QCMM workflow depends on. A reliable QCMM configuration keeps Joomla authoritative for users, groups, access levels, sessions, mail transport, and Scheduled Tasks while QCMM owns Plan, subscription, billing, scheduling, Meeting, Custom Field, resource, and member-facing state.

For Authorized Domains and Keyless QCMM Entitlement, verify the behavior with the role that will actually use it. Administrator, member, Host, and Fulfillment Editor experiences intentionally differ. A successful test as Super User does not prove that a normal user has the correct ownership, access, timing, or feature entitlement.

Permissions, Entitlement, and Data Safety

  • Joomla menu access, QCMM object ownership/access, role-specific permissions, and commercial feature entitlement are separate checks.
  • QCMM re-authorizes state-changing requests server-side; never treat a visible or hidden frontend control as the security boundary.
  • Do not expose PayPal credentials, encrypted settings, legacy keys, private room credentials, or other secrets in screenshots, URLs, public documentation, or community posts.
  • Preserve subscription, billing, booking, attendance, Custom Field, credit, and entitlement history when correcting a problem; current QCMM is designed to repair in place rather than erase evidence.
  • When Effective tier falls, premium configuration/history is preservation-first: features can become unavailable without deleting the saved data.

Verify the Result

  • QCMM reports version 2.0.21 and the intended Base/Effective tier.
  • The five canonical QCMM Scheduled Tasks exist and the Entitlement Revalidation task is structurally healthy at 60 minutes.
  • Frontend menu routes open only for their intended Joomla access levels.
  • A representative membership purchase/activation reaches Member Area and the expected Joomla groups without administrator-only shortcuts.

Common Mistakes to Avoid

  • Using old instructions that ask customers to paste a current license key into Joomla instead of using Authorized Domains.
  • Assuming install, page views, entitlement refresh, or Scheduled Tasks silently start the one-time Max Preview.
  • Testing only as Super User and treating that as proof that normal members, Hosts, or Fulfillment Editors have correct access.
  • Uninstalling before an ordinary upgrade instead of installing the current outer package over the existing installation.

Troubleshooting

  • Distinguish an authoritative Basic/invalid result from a retryable QuantaCade transport failure; do not preserve premium access indefinitely from stale local state.
  • Check for missing, disabled, duplicate, structurally invalid, or slower-than-hourly Entitlement Revalidation when premium controls disappear.
  • Reproduce the exact action with the smallest safe test and record the user role, Plan/subscription/booking/billing identifiers, current state, and time zone where relevant.
  • If a control is missing, check Joomla access, QCMM permission/ownership, record state, Effective tier, and task health before assuming packaged files are damaged.
  • If behavior is asynchronous, inspect the owning Scheduled Task and its last result instead of repeatedly performing the business action.
  • After a correction, rerun the same scenario from the real frontend; a successful Administrator save alone is not end-to-end verification.

Operational Best Practice

Keep a small regression checklist for Plans, checkout, Member Area, lifecycle tasks, billing, and any enabled Scheduling/Meeting features. Before a QCMM or Joomla update, maintain a current backup, record the installed versions and task state, and test with normal roles instead of relying only on Super User access.


Community Discussion

Want to compare membership or Meeting workflows, share practical QCMM tips, or discuss how other Joomla site owners use this feature? Visit the QC Memberships & Meetings Community. For private support, bug reports, account-specific entitlement or billing problems, or feature requests, use the QuantaCade support system.