Use the Upload Only Workspace Role
This article shows how to grant a constrained role intended to place content into authorized storage without normal browsing or download rights, including upload, create-folder, and inbound copy/move behavior.
What you need to know
- QCSB ships named Workspace roles as practical presets; server-side authorization still resolves the current user, Workspace, connection, source/destination direction, and any custom/override rule on every request.
Current Workspace role presets
| Role | What it allows |
|---|---|
| Upload Only | Upload, create folders, copy in, and move in. Cannot browse, download, edit, or delete existing files. |
| Viewer | Browse, preview, search, and download. Cannot upload or change files. |
| Contributor | Viewer access plus upload, create folders, copy in, and copy out. Cannot move, rename, replace, or delete. |
| Editor | Contributor access plus move in/out, rename, replace, and delete. No Recovery Vault management or activity/package controls. |
| Manager | Full role including recovery restore/purge and the broader management permission set. |
| Custom Permissions | Only the individual permissions explicitly configured for that Joomla group. |
How to do it
- Open Components → QC Storage Bridge → Workspaces and edit the Workspace.
- Under Allowed user groups, add or locate the Joomla group that should receive this access.
- Set its Workspace role to Upload Only. This preset is intended to provide upload/create folders/copy or move content into the authorized connection without ordinary browse/download access.
- Review any connection-specific override for that same group; an override or No Access can narrow the general Workspace role for one connection.
- Save the Workspace, then sign in as a representative normal user from that Joomla group and confirm both the actions that are available and the actions that are correctly absent.
Verify the result
- The provider reflects the intended final file/folder state.
- The QCSB result reaches the expected outcome without an unresolved sanitized error.
Important limits and mistakes to avoid
- A successful Super User test does not prove a normal Joomla group has correct Workspace access. Test with the real role.
Troubleshooting
- If an action is missing/denied, check Joomla menu access, Workspace allowed group, Workspace role, custom denies, connection override, and plan gate separately.
- If a file action fails, retry with one small test item and read Transfer Details or the operation toast before changing global settings.
Community Discussion
For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.