How QCST Protects Attachments and Blocks Dangerous File Types

This article explains non-public storage, never-allowed executable/active extensions, MIME/size/checksum checks, and authorized streaming.

Where this fits in QC Support Ticket

QCST treats attachments as protected support data, not normal public media. Upload policy, file/MIME checks, protected storage and authorized streaming work together so a renamed or directly guessed file is not automatically downloadable.

Primary location: QC Support Ticket frontend and administrator interfaces, depending on the permission or failure being tested.

Before you begin

  • Review the site-wide attachment size and extension policy first; field/mailbox-specific limits can be stricter but should not be expected to bypass the global protected-file rules.

Attachment safety chain

  • Configured extension/count/size rules reject obviously disallowed uploads.
  • QCST applies file/MIME validation and blocks dangerous executable/active content classes rather than trusting a renamed extension.
  • Stored attachments are kept outside ordinary public delivery paths.
  • Downloads go through QCST authorization and controlled streaming.
  • Integrity/checksum metadata used by the current implementation helps detect mismatched stored content.

Important behavior and limits

  • Never loosen attachment rules merely to make an unsafe file upload succeed; use a safe archive/alternate transfer method when support genuinely needs a blocked file type.

Verify the result

  • An allowed test file within size limits uploads and downloads through the authorized ticket path.
  • A disallowed extension or over-limit file is rejected without becoming directly web-accessible.
  • Repeat the test with the least-privileged normal role affected by the feature; do not rely only on Super User behavior.

If it does not work as expected

  • If upload fails, compare the file-field/mailbox limit with the global attachment maximum and extension allowlist; also check MIME/type validation.

Why extension allowlists are not enough by themselves

A filename can be misleading. QCST therefore combines configured extension/count/size rules with file/MIME checks and protected storage rather than trusting the suffix alone. If a legitimate support artifact uses a blocked active/executable type, use an approved safer transfer/archive method instead of adding dangerous types to the normal ticket-upload policy.


Community Discussion

For practical QC Support Ticket workflows and discussion with other Joomla site owners, visit the QC Support Ticket Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.