How QCST Protects Attachments and Blocks Dangerous File Types
This article explains non-public storage, never-allowed executable/active extensions, MIME/size/checksum checks, and authorized streaming.
Where this fits in QC Support Ticket
QCST treats attachments as protected support data, not normal public media. Upload policy, file/MIME checks, protected storage and authorized streaming work together so a renamed or directly guessed file is not automatically downloadable.
Primary location: QC Support Ticket frontend and administrator interfaces, depending on the permission or failure being tested.
Before you begin
- Review the site-wide attachment size and extension policy first; field/mailbox-specific limits can be stricter but should not be expected to bypass the global protected-file rules.
Attachment safety chain
- Configured extension/count/size rules reject obviously disallowed uploads.
- QCST applies file/MIME validation and blocks dangerous executable/active content classes rather than trusting a renamed extension.
- Stored attachments are kept outside ordinary public delivery paths.
- Downloads go through QCST authorization and controlled streaming.
- Integrity/checksum metadata used by the current implementation helps detect mismatched stored content.
Important behavior and limits
- Never loosen attachment rules merely to make an unsafe file upload succeed; use a safe archive/alternate transfer method when support genuinely needs a blocked file type.
Verify the result
- An allowed test file within size limits uploads and downloads through the authorized ticket path.
- A disallowed extension or over-limit file is rejected without becoming directly web-accessible.
- Repeat the test with the least-privileged normal role affected by the feature; do not rely only on Super User behavior.
If it does not work as expected
- If upload fails, compare the file-field/mailbox limit with the global attachment maximum and extension allowlist; also check MIME/type validation.
Why extension allowlists are not enough by themselves
A filename can be misleading. QCST therefore combines configured extension/count/size rules with file/MIME checks and protected storage rather than trusting the suffix alone. If a legitimate support artifact uses a blocked active/executable type, use an approved safer transfer/archive method instead of adding dangerous types to the normal ticket-upload policy.
Community Discussion
For practical QC Support Ticket workflows and discussion with other Joomla site owners, visit the QC Support Ticket Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.