How QCSB Isolates Private Connection Ownership
This article explains owner binding throughout listing, editing, file operations, and preference storage so one authenticated user cannot enumerate or use another user’s private connection.
What you need to know
- My Private Storage requires Max/All Access and supports user-owned FTP, SFTP, Google Drive, and OneDrive connections. Local storage remains administrator-created only.
- Private connection ownership is enforced server-side. Private connections cannot be inserted into administrator shared Workspaces even if request/database values are manipulated.
Ownership boundary
- A private connection is created in the signed-in user’s private-storage context and stored with that owner relationship.
- List/edit/test/connect/disconnect/delete actions resolve the current user and reject another user’s private connection ID.
- OAuth state for private Google/OneDrive authorization binds the flow to the intended private connection/owner rather than accepting an arbitrary callback target.
- Frontend item/path requests are revalidated against the owner’s private connection before provider access.
Verify the result
- Test Connection succeeds.
- The displayed/usable root is exactly the intended root and no parent folder is reachable.
- A normal authorized user can perform only the operations intended for that connection/Workspace role.
Important limits and mistakes to avoid
- Never broaden a connection root merely to work around a permission or provider error; fix the actual root/credential/hosting problem.
- Do not copy administrator or another user’s provider credentials into a private connection as a shortcut; private connections are intentionally isolated.
Troubleshooting
- If the provider is unreachable, test the connection in Administrator before troubleshooting the Workspace UI.
- Keep passwords, OAuth secrets/tokens, private keys, and unrestricted private paths out of public screenshots and support posts.
Community Discussion
For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.