Signed QCSB Item References and Why Frontend Paths Are Not Trusted
This article explains user/workspace/location/path/expiry-bound signed item references and why a client cannot safely authorize a file operation merely by submitting a provider path.
What you need to know
- Google Drive/OneDrive deep navigation can carry signed short-lived provider object identifiers. The signature binds the object ID to the user, Workspace, location, relative path, and expiration so a modified token is rejected.
What a signed reference binds
- The current Joomla user/session context.
- The Workspace and storage location.
- The provider object identifier and relative path represented by the control.
- An expiration/short validity window so old references cannot be reused indefinitely.
What happens when it is changed or stale
QCSB rejects a modified, expired, cross-user, cross-Workspace, or mismatched location/item reference before treating it as authority to contact the provider. A friendly path or hidden form value from the browser is therefore input to validate, not permission.
Community Discussion
For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.