Joomla Menu Access vs QCSB Workspace Access
This article explains that Joomla menu access and QCSB Workspace rules are cumulative: seeing a menu link does not bypass Workspace authorization and hiding a link does not grant file access.
Both layers must allow the user
| Layer | Effect |
|---|---|
| Joomla menu Access | Determines whether the user can reach/see the menu route according to Joomla access levels. |
| QCSB Workspace rules | Determine whether the user’s Joomla group is allowed and what actions that group may perform. |
| Connection override | Can narrow/replace the Workspace role for one selected Storage Connection. |
| Server-side action check | Revalidates the requested operation even if a button or URL is manually altered. |
Verify the result
- An allowed normal account can open the intended Workspace.
- An account outside the allowed rules cannot use the Workspace/action.
- Connection overrides and source/destination permissions behave exactly as configured.
Important limits and mistakes to avoid
- A successful Super User test does not prove a normal Joomla group has correct Workspace access. Test with the real role.
Troubleshooting
- If an action is missing/denied, check Joomla menu access, Workspace allowed group, Workspace role, custom denies, connection override, and plan gate separately.
Community Discussion
For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.