Why Production Push Requires a Joomla Super User
Production push changes the live Joomla site, so QCUL 1.01.14 requires a Joomla Super User in addition to the relevant QCUL operation permission.
Why the requirement is stricter than lab review
Laboratory viewing/testing can be delegated through focused component ACL, but production installation and production rollback can modify live files, database schema/data, site availability, and update state. QCUL therefore adds an explicit Super User requirement at the server action layer.
Authorization is rechecked
- Joomla user identity and QCUL operation permission.
- Super User status for production push/rollback.
- Joomla CSRF token on state-changing POST actions.
- Exact tested run/plan/item and current production state.
Recommended policy
Keep production push and rollback limited to a small maintenance group. Reviewers can receive View Laboratories/Download Reports without live-site authority.
Production change rule
For Why Production Push Requires a Joomla Super User, the live site should change only through the explicit tested-item production workflow after current readiness checks pass. Do not substitute a new package, skip the review/protection decision, or run a second production action while QCUL already owns an active push/rollback state.
Community Discussion
Want to compare update-testing workflows, share practical tips, or discuss how you use this QCUL feature? Visit the QC Update Laboratory Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.