Storage Connections and the Exact-Root Security Model

This article explains that each Storage Connection represents one provider plus one exact root, that QCSB never exposes or infers parent directories, and that every browse or file operation remains bounded to that configured root.

What you need to know

  • Each Storage Connection represents one provider and one exact root. QCSB normalizes paths and refuses navigation/operations outside that boundary.
  • Allow access to subdirectories controls depth below the root; it never exposes or infers parent directories above the root.

Exact-root rule

  1. An administrator creates one Storage Connection for one provider and saves an Exact root path.
  2. QCSB normalizes that root through the provider service and treats it as the highest reachable boundary for that connection.
  3. Allow access to subdirectories may permit descendants below the root; it never exposes the parent above it.
  4. Every browse or file operation is resolved against the saved connection/root again on the server rather than trusting a browser-supplied path.
  5. When another parent/sibling tree is needed, create another Storage Connection to that exact root rather than broadening navigation above the original boundary.

Verify the result

  • Test Connection succeeds.
  • The displayed/usable root is exactly the intended root and no parent folder is reachable.
  • A normal authorized user can perform only the operations intended for that connection/Workspace role.

Important limits and mistakes to avoid

  • Never broaden a connection root merely to work around a permission or provider error; fix the actual root/credential/hosting problem.

Troubleshooting

  • If the provider is unreachable, test the connection in Administrator before troubleshooting the Workspace UI.
  • Keep passwords, OAuth secrets/tokens, private keys, and unrestricted private paths out of public screenshots and support posts.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.