Download a QCST Attachment Safely
This article explains authorization checks, protected storage/streaming, and why copying a storage path or guessing a URL does not bypass ticket access.
Where this fits in QC Support Ticket
QCST keeps the customer conversation, private staff notes, and system workflow history distinct. Public replies can be shown to the customer; Pro Internal Notes remain staff-only; system timeline entries document events such as assignment, status, relationship, merge, or split operations.
Attachments are not meant to be treated as public media URLs. QCST validates extension/MIME/size policy, stores files in protected storage, records integrity information, and streams downloads only after ticket authorization is rechecked.
Primary location: QC Support Ticket Agent Queue ticket detail, with global attachment/settings controls under Settings.
Before you begin
- Review the site-wide attachment size and extension policy first; field/mailbox-specific limits can be stricter but should not be expected to bypass the global protected-file rules.
How to do it
- Open the ticket through Support Portal, verified guest access or Agent Queue as an authorized user.
- Click the attachment link from the ticket timeline/attachment container.
- QCST rechecks ticket ownership/guest authorization/Agent Department scope before streaming the file.
- Confirm the browser receives the expected file. A copied internal storage path or guessed public URL should not be treated as a valid download mechanism.
Important behavior and limits
- Public replies are customer-visible; Pro Internal Notes remain staff-only. System timeline entries record workflow events separately from the conversation.
- Attachments are stored outside normal public delivery and are streamed only after QCST rechecks ticket authorization.
- Never loosen attachment rules merely to make an unsafe file upload succeed; use a safe archive/alternate transfer method when support genuinely needs a blocked file type.
Verify the result
- An allowed test file within size limits uploads and downloads through the authorized ticket path.
- A disallowed extension or over-limit file is rejected without becoming directly web-accessible.
If it does not work as expected
- If upload fails, compare the file-field/mailbox limit with the global attachment maximum and extension allowlist; also check MIME/type validation.
Community Discussion
For practical QC Support Ticket workflows and discussion with other Joomla site owners, visit the QC Support Ticket Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.