How QCTNH Protects Its Local Service Credential

QCTNH protects its local service credential with authenticated encryption derived from the Joomla configuration secret rather than storing the raw credential as plain text.

Credential creation

When needed, QCTNH generates a service secret using 32 random bytes represented as hexadecimal text. It is separate from the Joomla WebCron key and identifies/authenticates QCTNH service messages.

Local encryption

  • Cipher: AES-256-GCM.
  • Encryption key material is derived from Joomla’s configuration secret plus a QCTNH-specific context string.
  • Authenticated additional data identifies the QCTNH local credential format.
  • The encrypted value includes the data necessary to decrypt/verify it but not the Joomla configuration secret itself.

Backup implication

A full Joomla backup normally carries both the encrypted QCTNH value and the Joomla configuration secret needed to decrypt it. Clone/origin protection is therefore still necessary: encryption at rest does not by itself stop a restored clone from possessing the same local secret.

Security boundary

How QCTNH Protects Its Local Service Credential is part of a deliberately narrow remote-execution boundary. QuantaCade is allowed to call only the registered public Joomla native WebCron route, on the registered origin, using the site’s WebCron credential. Public-IP and exact-route validation keep that service from becoming a general-purpose request proxy.

That boundary is why private/reserved addresses, unexpected query parameters, unrelated paths, and redirect-dependent destinations are rejected rather than “made to work.”


Community Discussion

Want to compare scheduler workflows, share practical tips, or discuss how you use this QCTNH feature? Visit the QC Task Nudge & Health Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.