Understand the QCST Security Model

This article explains customer ownership, verified guest access, department-scoped Agents, Joomla ACL, server-side authorization, CSRF/session checks, protected attachments, and private administrator controls.

Where this fits in QC Support Ticket

QCST treats visible IDs, form fields, buttons, and URLs as input—not as authority. Customer ownership, verified guest signatures, Agent Department scope, Joomla ACL, session tokens, and ticket/file authorization are revalidated server-side before protected actions complete.

Primary location: QC Support Ticket frontend and administrator interfaces, depending on the permission or failure being tested.

Security layers

LayerProtection
Customer ownershipRegistered customers can act on their own ticket records only.
Verified guest accessSigned/expiring verification/access is limited to the intended guest ticket.
Agent scopeActive QCST Agent + Department scope is rechecked for every ticket action.
Joomla ACLControls component/settings/license/ticket/organization/response capabilities.
CSRF/sessionJoomla session tokens protect state-changing form requests.
AttachmentsProtected non-public storage plus validation and authorized streaming.
Administrator controlsMailbox credentials, entitlement, organization and other sensitive configuration stay in administrator-authorized surfaces.

What to remember

  • Use least-privileged normal accounts when validating authorization; Super User behavior cannot prove that customer, guest or Agent boundaries are correct.

Defense in depth

No single visible value is treated as sufficient authorization. QCST combines Joomla authentication/ACL, customer ownership, signed guest access, active Agent records and Department scope, session/CSRF tokens, record revalidation and protected file streaming. A failure in one client-side assumption therefore should not automatically expose another customer’s ticket or attachment.

Administrator security responsibilities

  • Grant QCST administrator ACL actions only to Joomla groups that need them.
  • Keep inbound mailbox credentials and entitlement/organization configuration in authorized administrator surfaces.
  • Use normal customer/Agent accounts for permission testing; Super User is not a meaningful least-privilege test.
  • Keep Joomla/PHP/QCST updated and review Status/Scheduled Tasks rather than weakening authorization when a workflow fails.

Security boundaries worth testing

BoundaryExpected result
Customer A vs Customer BEach registered customer can work only the requester-owned ticket.
Verified guest linkThe signed/expiring link grants access only to the intended guest ticket.
Agent Department A vs BThe Agent can act only on ticket Departments inside current scope.
Attachment URL/referenceA guessed identifier is not enough; QCST authorizes the ticket/file request before streaming.
Administrator ACLA Joomla user without the required QCST action cannot use that administrator function simply by knowing its URL.

Community Discussion

For practical QC Support Ticket workflows and discussion with other Joomla site owners, visit the QC Support Ticket Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.