How QCTNH Validates the Exact Native Joomla WebCron Route

QCTNH accepts only the exact Joomla WebCron route shapes needed for System - Schedule Runner, rather than trusting an arbitrary path simply because it is on the same hostname.

Accepted native route characteristics

Routing modeExpected shape
Non-SEF/index.php with option=com_ajax, plugin=RunSchedulerWebcron, group=system, and format=json.
SEFA Joomla AJAX component path such as /component/ajax or /index.php/component/ajax, with the same scheduler plugin/group/format query values.

Registration endpoint restrictions

The base endpoint is validated without the authentication hash parameter and may not contain unexpected query parameters. The worker later appends the registered WebCron key as hash=... when it executes a wake-up.

Why admins should let Joomla build the URL

QCTNH uses Joomla routing to generate this route, which automatically respects SEF mode and a Joomla base subdirectory. Hand-building the URL is more error-prone and can fail the exact-route validation.

Defense in depth

The controls relevant to How QCTNH Validates the Exact Native Joomla WebCron Route are layered: HTTPS/TLS protects transport, endpoint/origin validation constrains the destination, WebCron hash authenticates Joomla WebCron, the per-installation service secret signs service messages, timestamps/nonces limit replay, and clone protection prevents silent identity adoption.

A failure in one layer should be repaired at that layer instead of disabling the others for convenience.


Community Discussion

Want to compare scheduler workflows, share practical tips, or discuss how you use this QCTNH feature? Visit the QC Task Nudge & Health Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.