How Replay Protection and Same-Site Heartbeats Reduce Abuse
Replay protection and same-site heartbeat validation reduce two different abuse risks: replaying authenticated service messages and using the public site as a cross-site trigger for operational check-ins.
Replay protection
Authenticated service requests include a nonce and timestamp. QCTNH records seen nonces and rejects duplicates; old nonce records are cleaned after the replay-protection horizon. The signature window is five minutes, while nonce cleanup retains recent history long enough to prevent immediate reuse.
Same-site frontend heartbeat
The system plugin’s browser heartbeat endpoint validates the request’s Origin or Referer host against the current site. Cross-site hosts are rejected with HTTP 403. The heartbeat is also locally throttled to roughly once every six hours.
What these controls do not replace
They complement—not replace—HTTPS, secure Joomla configuration, WebCron-key secrecy, public-IP/route validation, and normal web-application defenses.
Public service assumption
How Replay Protection and Same-Site Heartbeats Reduce Abuse assumes QuantaCade can safely reach the Joomla site from the public Internet. Private development environments can still use Joomla Scheduler through local/CLI/server-cron mechanisms, but they are intentionally outside the central Task Nudge wake-up model.
This is a product security constraint, not a licensing restriction; QCTNH remains free.
Community Discussion
Want to compare scheduler workflows, share practical tips, or discuss how you use this QCTNH feature? Visit the QC Task Nudge & Health Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.