Why Production Push Requires a Joomla Super User

Production push changes the live Joomla site, so QCUL 1.01.14 requires a Joomla Super User in addition to the relevant QCUL operation permission.

Why the requirement is stricter than lab review

Laboratory viewing/testing can be delegated through focused component ACL, but production installation and production rollback can modify live files, database schema/data, site availability, and update state. QCUL therefore adds an explicit Super User requirement at the server action layer.

Authorization is rechecked

  • Joomla user identity and QCUL operation permission.
  • Super User status for production push/rollback.
  • Joomla CSRF token on state-changing POST actions.
  • Exact tested run/plan/item and current production state.

Recommended policy

Keep production push and rollback limited to a small maintenance group. Reviewers can receive View Laboratories/Download Reports without live-site authority.

Production change rule

For Why Production Push Requires a Joomla Super User, the live site should change only through the explicit tested-item production workflow after current readiness checks pass. Do not substitute a new package, skip the review/protection decision, or run a second production action while QCUL already owns an active push/rollback state.


Community Discussion

Want to compare update-testing workflows, share practical tips, or discuss how you use this QCUL feature? Visit the QC Update Laboratory Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.