Exact Roots and Subdirectory Access in My Private Storage

This article explains that private connections use the same exact-root boundary as shared connections and that Allow Subdirectories changes depth only below that root.

What you need to know

  • Each Storage Connection represents one provider and one exact root. QCSB normalizes paths and refuses navigation/operations outside that boundary.
  • Allow access to subdirectories controls depth below the root; it never exposes or infers parent directories above the root.
  • My Private Storage requires Max/All Access and supports user-owned FTP, SFTP, Google Drive, and OneDrive connections. Local storage remains administrator-created only.
  • Private connection ownership is enforced server-side. Private connections cannot be inserted into administrator shared Workspaces even if request/database values are manipulated.

Private roots use the same hard boundary

  1. When creating the private FTP/SFTP/Google Drive/OneDrive connection, the owner enters the exact provider root intended for that private view.
  2. QCSB binds the saved private connection to that root and owner.
  3. Allowing subdirectories permits descendants below the saved root; it never turns the connection into unrestricted access to provider parents.
  4. Folder/item references are revalidated with the current owner and private connection context before provider access.
  5. If the owner needs a different unrelated root, create another private connection instead of escaping upward from the existing one.

Verify the result

  • The owner can see/use the private connection.
  • Another normal Joomla user cannot see or use that owner’s private connection.
  • Private connections do not appear as selectable connections in administrator shared Workspaces.

Important limits and mistakes to avoid

  • Never broaden a connection root merely to work around a permission or provider error; fix the actual root/credential/hosting problem.
  • Do not copy administrator or another user’s provider credentials into a private connection as a shortcut; private connections are intentionally isolated.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.