How QCSB Prevents Path Traversal Outside a Connection Root

This article explains root normalization, bounded path resolution, provider-specific identifiers, and server-side validation that stop crafted relative paths from escaping the exact configured Storage Connection root.

Server-side boundary

  • Local paths are normalized and resolved against the configured root before filesystem access.
  • FTP/SFTP absolute/relative provider paths are validated as remaining inside the configured remote root.
  • Google Drive/OneDrive navigation uses verified roots plus provider object IDs rather than trusting a browser-supplied friendly path.
  • Allow Subdirectories can permit descendants below the root, never the parent above it.
  • Forged relative paths, modified provider tokens, or stale browser URLs are revalidated before provider contact.

Customer implication

When a user cannot reach a parent folder, that is the intended security model. Create a separate Storage Connection to another exact root instead of trying to navigate upward from an existing connection.

Verify the result

  • Test Connection succeeds.
  • The displayed/usable root is exactly the intended root and no parent folder is reachable.
  • A normal authorized user can perform only the operations intended for that connection/Workspace role.

Important limits and mistakes to avoid

  • Never broaden a connection root merely to work around a permission or provider error; fix the actual root/credential/hosting problem.

Troubleshooting

  • If the provider is unreachable, test the connection in Administrator before troubleshooting the Workspace UI.
  • Keep passwords, OAuth secrets/tokens, private keys, and unrestricted private paths out of public screenshots and support posts.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.