Who Uses QC Storage Bridge: Administrators, Shared Workspace Users, and Private Storage Users
This article defines the practical roles of Joomla administrators, users of administrator-published Workspaces, and Max users of My Private Storage, including where configuration authority ends and frontend file access begins.
What you need to know
- My Private Storage requires Max/All Access and supports user-owned FTP, SFTP, Google Drive, and OneDrive connections. Local storage remains administrator-created only.
- Private connection ownership is enforced server-side. Private connections cannot be inserted into administrator shared Workspaces even if request/database values are manipulated.
Roles and boundaries
| User type | What that user controls |
|---|---|
| Joomla / QCSB administrator | Creates Storage Connections and exact roots, creates Workspaces, assigns Joomla groups/roles/overrides, manages entitlement/tasks/settings, and—when entitled—manages the Recovery Vault. |
| Shared Workspace user | Uses only the frontend File Workspace(s) published to the user’s Joomla access/group context. The user never receives provider credentials and can perform only the QCSB operations allowed by the effective Workspace rules. |
| My Private Storage user | On Max/All Access, creates and owns personal FTP/SFTP/Google Drive/OneDrive connections from the frontend private-storage area. Other users and administrator shared Workspaces cannot silently reuse those private credentials/connections. |
Important separation
Administrator access to configure QCSB is not the same as frontend file permission. Likewise, being able to see a Joomla menu item does not automatically authorize a Workspace action; QCSB resolves the current Workspace/group/role/override and rechecks the operation server-side.
Verify the result
- An allowed normal account can open the intended Workspace.
- An account outside the allowed rules cannot use the Workspace/action.
- Connection overrides and source/destination permissions behave exactly as configured.
Important limits and mistakes to avoid
- Do not copy administrator or another user’s provider credentials into a private connection as a shortcut; private connections are intentionally isolated.
- A successful Super User test does not prove a normal Joomla group has correct Workspace access. Test with the real role.
Troubleshooting
- If an action is missing/denied, check Joomla menu access, Workspace allowed group, Workspace role, custom denies, connection override, and plan gate separately.
Community Discussion
For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.