How QCSB Isolates Private Credentials and OAuth Tokens

This article explains per-private-connection encrypted secret/token storage and why private provider credentials are never converted into shared administrator credentials.

What you need to know

  • Provider credentials are stored per connection and are not sent back to ordinary frontend users. Secret-bearing error text is sanitized before it is shown or persisted for user-facing diagnostics.
  • Private Connections use separate per-user credentials/tokens; administrator OAuth credentials and another user’s private credentials are not silently reused.
  • My Private Storage requires Max/All Access and supports user-owned FTP, SFTP, Google Drive, and OneDrive connections. Local storage remains administrator-created only.
  • Private connection ownership is enforced server-side. Private connections cannot be inserted into administrator shared Workspaces even if request/database values are manipulated.

Credential isolation

  • Private FTP/SFTP passwords/keys and cloud OAuth application/token data belong to the owner’s private connection record, not a shared administrator connection.
  • Secret values are not returned as reusable plaintext to another frontend user.
  • Google/OneDrive authorization uses one-time protected OAuth state/PKCE and binds the resulting token set to the intended private connection/owner.
  • Deleting the QCSB private connection removes the local relationship/secrets according to the product workflow but does not delete the provider’s actual files.

Verify the result

  • The owner can see/use the private connection.
  • Another normal Joomla user cannot see or use that owner’s private connection.
  • Private connections do not appear as selectable connections in administrator shared Workspaces.

Important limits and mistakes to avoid

  • Do not copy administrator or another user’s provider credentials into a private connection as a shortcut; private connections are intentionally isolated.

Troubleshooting

  • Keep passwords, OAuth secrets/tokens, private keys, and unrestricted private paths out of public screenshots and support posts.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.