HTTP Support, Standard Ports, and Transport Limitations

QCTNH can represent HTTP or HTTPS origins, but the current service validation expects the standard port for the selected scheme and HTTPS is the recommended production transport.

Supported transport expectations

OriginExpectation
HTTPSStandard HTTPS port (443) with a valid certificate and public DNS. Preferred for production.
HTTPStandard HTTP port (80). Supported by current validation but does not provide TLS confidentiality/authentication.
Non-standard portsCurrent central origin validation rejects non-standard scheme ports for service registration.

Why the restriction exists

The service deliberately narrows what public targets can be registered. Combined with exact host/scheme matching, public-IP validation, and route validation, this reduces the chance that the Task Nudge service is abused as a generic network request proxy.

If your Joomla site uses a custom external port

Use a normal public reverse proxy/canonical URL on the standard port, or use another scheduler trigger such as server cron. Do not try to bypass the validation by manually rewriting the stored endpoint.

Defense in depth

The controls relevant to HTTP Support, Standard Ports, and Transport Limitations are layered: HTTPS/TLS protects transport, endpoint/origin validation constrains the destination, WebCron hash authenticates Joomla WebCron, the per-installation service secret signs service messages, timestamps/nonces limit replay, and clone protection prevents silent identity adoption.

A failure in one layer should be repaired at that layer instead of disabling the others for convenience.


Community Discussion

Want to compare scheduler workflows, share practical tips, or discuss how you use this QCTNH feature? Visit the QC Task Nudge & Health Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.