Understand QCST Attachment Type, MIME, Size, and Checksum Validation

This article explains the practical security checks and why executable/active-content file types remain blocked even if renamed.

Where this fits in QC Support Ticket

QCST keeps the customer conversation, private staff notes, and system workflow history distinct. Public replies can be shown to the customer; Pro Internal Notes remain staff-only; system timeline entries document events such as assignment, status, relationship, merge, or split operations.

Attachments are not meant to be treated as public media URLs. QCST validates extension/MIME/size policy, stores files in protected storage, records integrity information, and streams downloads only after ticket authorization is rechecked.

Primary location: QC Support Ticket Agent Queue ticket detail, with global attachment/settings controls under Settings.

Before you begin

  • Review the site-wide attachment size and extension policy first; field/mailbox-specific limits can be stricter but should not be expected to bypass the global protected-file rules.

Attachment validation layers

  • Configured extension/size/count rules are checked first.
  • QCST does not rely only on a filename extension; MIME/type and upload validation are part of the safety path.
  • Dangerous executable/active-content file types remain blocked even if renamed to look harmless.
  • Accepted files are stored in protected storage and identified with integrity/checksum metadata where used by the current implementation.
  • Download is streamed only after the viewer is authorized for the ticket.

Important behavior and limits

  • Public replies are customer-visible; Pro Internal Notes remain staff-only. System timeline entries record workflow events separately from the conversation.
  • Attachments are stored outside normal public delivery and are streamed only after QCST rechecks ticket authorization.
  • Never loosen attachment rules merely to make an unsafe file upload succeed; use a safe archive/alternate transfer method when support genuinely needs a blocked file type.

Verify the result

  • An allowed test file within size limits uploads and downloads through the authorized ticket path.
  • A disallowed extension or over-limit file is rejected without becoming directly web-accessible.

If it does not work as expected

  • If upload fails, compare the file-field/mailbox limit with the global attachment maximum and extension allowlist; also check MIME/type validation.

Community Discussion

For practical QC Support Ticket workflows and discussion with other Joomla site owners, visit the QC Support Ticket Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.