Why HTTPS Is Strongly Recommended for QCTNH
HTTPS is strongly recommended because QCTNH’s central worker sends authenticated WebCron requests to your public Joomla site and should do so over verified TLS in production.
What HTTPS protects
- Confidentiality of the WebCron key in transit.
- Server identity through certificate validation.
- Integrity of the worker-to-Joomla HTTP request against network interception.
Worker TLS behavior
For HTTPS targets the production worker enables peer and hostname verification. Certificate errors are treated as connection failures rather than silently disabling verification. The worker also does not follow arbitrary redirects, so the registered URL should already be the final HTTPS endpoint.
Migration to HTTPS
HTTP→HTTPS changes the QCTNH local origin scheme. Finish the site’s HTTPS configuration first, then use Check WebCron and Test Connection from the final HTTPS canonical URL so the correct native endpoint is registered.
Security boundary
Why HTTPS Is Strongly Recommended for QCTNH is part of a deliberately narrow remote-execution boundary. QuantaCade is allowed to call only the registered public Joomla native WebCron route, on the registered origin, using the site’s WebCron credential. Public-IP and exact-route validation keep that service from becoming a general-purpose request proxy.
That boundary is why private/reserved addresses, unexpected query parameters, unrelated paths, and redirect-dependent destinations are rejected rather than “made to work.”
Community Discussion
Want to compare scheduler workflows, share practical tips, or discuss how you use this QCTNH feature? Visit the QC Task Nudge & Health Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.