Understand the QCST Security Model
This article explains customer ownership, verified guest access, department-scoped Agents, Joomla ACL, server-side authorization, CSRF/session checks, protected attachments, and private administrator controls.
Where this fits in QC Support Ticket
QCST treats visible IDs, form fields, buttons, and URLs as input—not as authority. Customer ownership, verified guest signatures, Agent Department scope, Joomla ACL, session tokens, and ticket/file authorization are revalidated server-side before protected actions complete.
Primary location: QC Support Ticket frontend and administrator interfaces, depending on the permission or failure being tested.
Security layers
| Layer | Protection |
|---|---|
| Customer ownership | Registered customers can act on their own ticket records only. |
| Verified guest access | Signed/expiring verification/access is limited to the intended guest ticket. |
| Agent scope | Active QCST Agent + Department scope is rechecked for every ticket action. |
| Joomla ACL | Controls component/settings/license/ticket/organization/response capabilities. |
| CSRF/session | Joomla session tokens protect state-changing form requests. |
| Attachments | Protected non-public storage plus validation and authorized streaming. |
| Administrator controls | Mailbox credentials, entitlement, organization and other sensitive configuration stay in administrator-authorized surfaces. |
What to remember
- Use least-privileged normal accounts when validating authorization; Super User behavior cannot prove that customer, guest or Agent boundaries are correct.
Defense in depth
No single visible value is treated as sufficient authorization. QCST combines Joomla authentication/ACL, customer ownership, signed guest access, active Agent records and Department scope, session/CSRF tokens, record revalidation and protected file streaming. A failure in one client-side assumption therefore should not automatically expose another customer’s ticket or attachment.
Administrator security responsibilities
- Grant QCST administrator ACL actions only to Joomla groups that need them.
- Keep inbound mailbox credentials and entitlement/organization configuration in authorized administrator surfaces.
- Use normal customer/Agent accounts for permission testing; Super User is not a meaningful least-privilege test.
- Keep Joomla/PHP/QCST updated and review Status/Scheduled Tasks rather than weakening authorization when a workflow fails.
Security boundaries worth testing
| Boundary | Expected result |
|---|---|
| Customer A vs Customer B | Each registered customer can work only the requester-owned ticket. |
| Verified guest link | The signed/expiring link grants access only to the intended guest ticket. |
| Agent Department A vs B | The Agent can act only on ticket Departments inside current scope. |
| Attachment URL/reference | A guessed identifier is not enough; QCST authorizes the ticket/file request before streaming. |
| Administrator ACL | A Joomla user without the required QCST action cannot use that administrator function simply by knowing its URL. |
Community Discussion
For practical QC Support Ticket workflows and discussion with other Joomla site owners, visit the QC Support Ticket Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.