Why Private Connections Cannot Be Added to Administrator Shared Workspaces

This article explains the deliberate separation that prevents one user’s personal provider account from being republished to other Joomla users through an administrator Workspace.

What you need to know

  • My Private Storage requires Max/All Access and supports user-owned FTP, SFTP, Google Drive, and OneDrive connections. Local storage remains administrator-created only.
  • Private connection ownership is enforced server-side. Private connections cannot be inserted into administrator shared Workspaces even if request/database values are manipulated.

Why the boundary exists

A shared Workspace is administrator publication for Joomla groups using administrator-created Storage Connections. A private connection is user-owned and can contain personal provider credentials. Allowing an administrator Workspace to attach another user’s private connection would break that ownership/credential boundary.

How QCSB enforces it

  • The Workspace editor lists administrator-created shared connections, not arbitrary user-private connections.
  • Private ownership is rechecked server-side; changing submitted IDs/database-facing request values does not turn a private record into a shared connection.
  • When collaboration is needed, create an administrator shared Storage Connection/Workspace to an appropriate provider root or transfer permitted files between the user’s private view and an already authorized shared destination.

Verify the result

  • Test Connection succeeds.
  • The displayed/usable root is exactly the intended root and no parent folder is reachable.
  • A normal authorized user can perform only the operations intended for that connection/Workspace role.

Important limits and mistakes to avoid

  • Never broaden a connection root merely to work around a permission or provider error; fix the actual root/credential/hosting problem.
  • Do not copy administrator or another user’s provider credentials into a private connection as a shortcut; private connections are intentionally isolated.
  • A successful Super User test does not prove a normal Joomla group has correct Workspace access. Test with the real role.

Troubleshooting

  • If the provider is unreachable, test the connection in Administrator before troubleshooting the Workspace UI.
  • If an action is missing/denied, check Joomla menu access, Workspace allowed group, Workspace role, custom denies, connection override, and plan gate separately.
  • Keep passwords, OAuth secrets/tokens, private keys, and unrestricted private paths out of public screenshots and support posts.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.