Understand QCSB Component ACL and Administrator Permissions

This article explains core manage/admin plus QCSB permissions for settings, entitlement, connections, locations, Workspaces, permissions, recovery, and audit viewing, including why Joomla backend access should be granted narrowly.

What you need to know

  • An explicit deny wins over allow, and no applicable allow means denied.
  • Frontend button visibility is only guidance. QCSB rechecks authorization server-side and rejects forged Workspace/location/item references.

Current component ACL actions

ACL actionPurpose
core.manageOpen/manage the QCSB component according to Joomla component access.
core.adminFull Joomla component configuration/ACL authority.
qcsb.manage_settingsManage QCSB settings.
qcsb.manage_licenseUse entitlement/licensing administration actions.
qcsb.manage_connectionsManage Storage Connections/provider credentials and roots.
qcsb.manage_locationsManage storage-location level configuration used by QCSB.
qcsb.manage_workspacesCreate/edit Workspace publication configuration.
qcsb.manage_permissionsManage QCSB Workspace permission profiles/overrides.
qcsb.manage_recoveryManage Recovery Vault operations where the current plan exposes them.
qcsb.view_auditView audit-oriented information where exposed by the current interface/services.

Grant narrowly

Give administrators only the backend capabilities their job requires. These component ACL actions govern QCSB administration; frontend file access is still determined separately by Joomla menu access plus Workspace group/role/override rules.

Verify the result

  • An allowed normal account can open the intended Workspace.
  • An account outside the allowed rules cannot use the Workspace/action.
  • Connection overrides and source/destination permissions behave exactly as configured.

Important limits and mistakes to avoid

  • A successful Super User test does not prove a normal Joomla group has correct Workspace access. Test with the real role.

Troubleshooting

  • If an action is missing/denied, check Joomla menu access, Workspace allowed group, Workspace role, custom denies, connection override, and plan gate separately.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.