Workspace Permission Testing and Go-Live Checklist

This article shows how to test representative Joomla accounts for browse, upload, download, copy/move, destructive operations, destination access, and denied connections before exposing a Workspace to its real audience.

What you need to know

  • An explicit deny wins over allow, and no applicable allow means denied.
  • Frontend button visibility is only guidance. QCSB rechecks authorization server-side and rejects forged Workspace/location/item references.

Checklist

  1. Create at least one test account for every Joomla group that will use the Workspace; do not rely on Super User testing.
  2. Confirm an allowed user can open the menu item and a user outside all allowed groups cannot.
  3. For each role, test only the actions it should have: browse/download, upload/create folder, copy, move/rename/delete, and Recovery management as appropriate.
  4. Test Copy and Move to a second connection so source and destination permissions are both exercised.
  5. Test one connection override and one explicit deny when those are used in production.
  6. Re-test after changing a Joomla group membership, because background continuation and new requests re-evaluate current authority.

Verify the result

  • An allowed normal account can open the intended Workspace.
  • An account outside the allowed rules cannot use the Workspace/action.
  • Connection overrides and source/destination permissions behave exactly as configured.

Important limits and mistakes to avoid

  • A successful Super User test does not prove a normal Joomla group has correct Workspace access. Test with the real role.

Troubleshooting

  • If an action is missing/denied, check Joomla menu access, Workspace allowed group, Workspace role, custom denies, connection override, and plan gate separately.

Community Discussion

For practical QCSB workflows and discussion with other Joomla site owners, visit the QC Storage Bridge Community. For private support, bug reports, account-specific entitlement issues, or feature requests, use the QuantaCade support system.