Understand QCSB Workspace Roles and Permission Resolution

This article introduces Upload Only, Viewer, Contributor, Editor, Manager, and Pro Custom roles, how they translate into file-operation permissions, and how connection overrides and explicit denies refine them.

What you need to know

  • QCSB ships named Workspace roles as practical presets; server-side authorization still resolves the current user, Workspace, connection, source/destination direction, and any custom/override rule on every request.
  • An explicit deny wins over allow, and no applicable allow means denied.
  • Frontend button visibility is only guidance. QCSB rechecks authorization server-side and rejects forged Workspace/location/item references.

Current Workspace role presets

RoleWhat it allows
Upload OnlyUpload, create folders, copy in, and move in. Cannot browse, download, edit, or delete existing files.
ViewerBrowse, preview, search, and download. Cannot upload or change files.
ContributorViewer access plus upload, create folders, copy in, and copy out. Cannot move, rename, replace, or delete.
EditorContributor access plus move in/out, rename, replace, and delete. No Recovery Vault management or activity/package controls.
ManagerFull role including recovery restore/purge and the broader management permission set.
Custom PermissionsOnly the individual permissions explicitly configured for that Joomla group.

Verify the result

  • An allowed normal account can open the intended Workspace.
  • An account outside the allowed rules cannot use the Workspace/action.
  • Connection overrides and source/destination permissions behave exactly as configured.

Important limits and mistakes to avoid

  • A successful Super User test does not prove a normal Joomla group has correct Workspace access. Test with the real role.

Troubleshooting

  • If an action is missing/denied, check Joomla menu access, Workspace allowed group, Workspace role, custom denies, connection override, and plan gate separately.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.