QCSB Server-Side Permission Enforcement and Tamper Resistance

This article explains that buttons being hidden or disabled is only a user-interface aid; every request is revalidated on the server so modified forms, URLs, or client-side scripts cannot grant unauthorized file actions.

What you need to know

  • An explicit deny wins over allow, and no applicable allow means denied.
  • Frontend button visibility is only guidance. QCSB rechecks authorization server-side and rejects forged Workspace/location/item references.

What is rechecked on a request

  • Current authenticated Joomla user and CSRF/session context for state-changing requests.
  • Current Effective tier and feature gate.
  • Workspace publication/allowed group role plus any custom permission or connection override.
  • Private-connection ownership where My Private Storage is involved.
  • Source and destination authorization separately for directional operations such as Copy/Move.
  • Exact-root/path or signed item reference before provider contact.

What this prevents

Changing a hidden form field, URL parameter, JavaScript request, Workspace/location ID, provider object ID, or destination value does not create authority. The server resolves the current objects and rejects a request whose submitted identifiers do not belong to the authorized context.

Verify the result

  • An allowed normal account can open the intended Workspace.
  • An account outside the allowed rules cannot use the Workspace/action.
  • Connection overrides and source/destination permissions behave exactly as configured.

Important limits and mistakes to avoid

  • A successful Super User test does not prove a normal Joomla group has correct Workspace access. Test with the real role.

Troubleshooting

  • If an action is missing/denied, check Joomla menu access, Workspace allowed group, Workspace role, custom denies, connection override, and plan gate separately.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.