Use the Upload Only Workspace Role

This article shows how to grant a constrained role intended to place content into authorized storage without normal browsing or download rights, including upload, create-folder, and inbound copy/move behavior.

What you need to know

  • QCSB ships named Workspace roles as practical presets; server-side authorization still resolves the current user, Workspace, connection, source/destination direction, and any custom/override rule on every request.

Current Workspace role presets

RoleWhat it allows
Upload OnlyUpload, create folders, copy in, and move in. Cannot browse, download, edit, or delete existing files.
ViewerBrowse, preview, search, and download. Cannot upload or change files.
ContributorViewer access plus upload, create folders, copy in, and copy out. Cannot move, rename, replace, or delete.
EditorContributor access plus move in/out, rename, replace, and delete. No Recovery Vault management or activity/package controls.
ManagerFull role including recovery restore/purge and the broader management permission set.
Custom PermissionsOnly the individual permissions explicitly configured for that Joomla group.

How to do it

  1. Open Components → QC Storage Bridge → Workspaces and edit the Workspace.
  2. Under Allowed user groups, add or locate the Joomla group that should receive this access.
  3. Set its Workspace role to Upload Only. This preset is intended to provide upload/create folders/copy or move content into the authorized connection without ordinary browse/download access.
  4. Review any connection-specific override for that same group; an override or No Access can narrow the general Workspace role for one connection.
  5. Save the Workspace, then sign in as a representative normal user from that Joomla group and confirm both the actions that are available and the actions that are correctly absent.

Verify the result

  • The provider reflects the intended final file/folder state.
  • The QCSB result reaches the expected outcome without an unresolved sanitized error.

Important limits and mistakes to avoid

  • A successful Super User test does not prove a normal Joomla group has correct Workspace access. Test with the real role.

Troubleshooting

  • If an action is missing/denied, check Joomla menu access, Workspace allowed group, Workspace role, custom denies, connection override, and plan gate separately.
  • If a file action fails, retry with one small test item and read Transfer Details or the operation toast before changing global settings.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.