Why QCSB Rechecks Permissions During Background Continuation

This article explains that continuation does not permanently inherit stale authority from submission time; QCSB re-evaluates the original user and current authorization before continuing eligible work.

What you need to know

  • An explicit deny wins over allow, and no applicable allow means denied.
  • Frontend button visibility is only guidance. QCSB rechecks authorization server-side and rejects forged Workspace/location/item references.
  • QCSB uses durable jobs but follows an immediate-first model: the request attempts ordinary work immediately, and only unfinished work remains for continuation.
  • Pro/Max/All Access can use the 5-minute Transfer Continuation task. The worker rechecks the original user’s current authority before contacting a provider.

Submission time is not permanent authority

A transfer may outlive the browser request that created it. Between submission and a later continuation run, the user can be disabled, removed from a Joomla group, lose a Workspace role/connection override, or the Effective tier/provider state can change. QCSB therefore re-resolves current authority before continuing rather than trusting the original request forever.

Result of a changed permission

If the required authority no longer exists, the worker must not contact the provider as if the old permission were still valid. The affected item/job reports a safe failure/warning state while already completed independent items remain completed.

Verify the result

  • An allowed normal account can open the intended Workspace.
  • An account outside the allowed rules cannot use the Workspace/action.
  • Connection overrides and source/destination permissions behave exactly as configured.

Important limits and mistakes to avoid

  • A successful Super User test does not prove a normal Joomla group has correct Workspace access. Test with the real role.

Troubleshooting

  • If an action is missing/denied, check Joomla menu access, Workspace allowed group, Workspace role, custom denies, connection override, and plan gate separately.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.