How QCSB Encrypts and Isolates Connection Credentials
This article explains per-connection secret storage, separation of connector credentials from ordinary configuration, and the operational rule that credentials should be managed through QCSB rather than exposed to frontend users.
What you need to know
- Provider credentials are stored per connection and are not sent back to ordinary frontend users. Secret-bearing error text is sanitized before it is shown or persisted for user-facing diagnostics.
- Private Connections use separate per-user credentials/tokens; administrator OAuth credentials and another user’s private credentials are not silently reused.
Credential boundary
- Each administrator Storage Connection stores only the credentials needed for its provider; ordinary frontend Workspace users are never given those raw provider secrets.
- Password/secret fields are not echoed back to the browser for routine editing. Leaving a saved secret field blank when editing keeps the existing secret where the current form says so.
- Google Drive and OneDrive access/refresh tokens are bound to the saved connection and protected OAuth state/callback flow.
- My Private Storage uses separate per-user secret records. An administrator shared connection and a user private connection do not silently share provider credentials.
- User-facing/provider errors are sanitized so secret-bearing responses are not copied into normal transfer/status messages.
Verify the result
- Test Connection succeeds.
- The displayed/usable root is exactly the intended root and no parent folder is reachable.
- A normal authorized user can perform only the operations intended for that connection/Workspace role.
Important limits and mistakes to avoid
- Never broaden a connection root merely to work around a permission or provider error; fix the actual root/credential/hosting problem.
Troubleshooting
- If the provider is unreachable, test the connection in Administrator before troubleshooting the Workspace UI.
- Keep passwords, OAuth secrets/tokens, private keys, and unrestricted private paths out of public screenshots and support posts.
Community Discussion
For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.