How QCSB Checks Both Source and Destination Permissions for Copy and Move
This article explains that cross-location operations require authorization on each side: source read/out authority and destination inbound authority are independently checked, with move also requiring source-removal authority.
What you need to know
- An explicit deny wins over allow, and no applicable allow means denied.
- Frontend button visibility is only guidance. QCSB rechecks authorization server-side and rejects forged Workspace/location/item references.
- Copy/Move authorization is directional: QCSB checks the source-side permission and the destination-side permission independently.
- Move is destructive only after the destination has been written and verified; the source is Recovery-protected before removal.
Directional authorization
| Side | What QCSB checks |
|---|---|
| Copy source | Requires authority to read/copy out of the source location. |
| Copy destination | Requires authority to copy/write in to the chosen destination. |
| Move source | Requires move-out/destructive authority; source removal happens only after destination verification and Recovery protection. |
| Move destination | Requires move-in/write authority for the chosen destination. |
| Destination picker | Only eligible destinations are offered, but a forged destination value is still rejected by the server-side authorization check. |
Verify the result
- An allowed normal account can open the intended Workspace.
- An account outside the allowed rules cannot use the Workspace/action.
- Connection overrides and source/destination permissions behave exactly as configured.
Important limits and mistakes to avoid
- Do not bypass failed recovery protection to force a destructive action. The block is intentional safety behavior.
- A successful Super User test does not prove a normal Joomla group has correct Workspace access. Test with the real role.
Troubleshooting
- If an action is missing/denied, check Joomla menu access, Workspace allowed group, Workspace role, custom denies, connection override, and plan gate separately.
- If a file action fails, retry with one small test item and read Transfer Details or the operation toast before changing global settings.
Community Discussion
For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.