QCSB Permission Keys Explained

This article provides a reference for the current permission vocabulary for browse, preview, search, upload, download, copy/move directions, create folder, rename, replace, delete, restore, purge, activity visibility and related advanced keys without presenting hidden schema-only features as standalone workflows.

What you need to know

  • An explicit deny wins over allow, and no applicable allow means denied.
  • Frontend button visibility is only guidance. QCSB rechecks authorization server-side and rejects forged Workspace/location/item references.

Permission groups

GroupPermission keys
View and findbrowse, preview, search, view activity
Add and receiveupload, create folder, copy in, move in
Download and transfer outdownload, copy out, move out, bulk export, package
Modifyrename, replace, delete
Recoveryrestore, purge

Why the direction matters

The copy_in/copy_out and move_in/move_out pairs let QCSB evaluate each side of a transfer independently. A user who may read/copy out of one connection does not automatically gain permission to write/copy in to another.

Verify the result

  • An allowed normal account can open the intended Workspace.
  • An account outside the allowed rules cannot use the Workspace/action.
  • Connection overrides and source/destination permissions behave exactly as configured.

Important limits and mistakes to avoid

  • A successful Super User test does not prove a normal Joomla group has correct Workspace access. Test with the real role.

Troubleshooting

  • If an action is missing/denied, check Joomla menu access, Workspace allowed group, Workspace role, custom denies, connection override, and plan gate separately.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.