Granting Manage Settings Permission

The Manage Settings Joomla ACL action lets you delegate one defined QCUL capability without automatically granting every laboratory or production operation.

What this permission controls

Manage Settings allows an authorized Joomla user group to change QCUL Settings, including default laboratory duration, lab creation speed, and the Undo Production Push availability window. QCUL checks permissions server-side; hiding or showing a button is not the security boundary.

Grant it through Joomla ACL

  1. Open System → Global Configuration or the QC Update Laboratory component permissions screen, depending on how you manage component ACL.
  2. Choose the Joomla user group that should receive the capability.
  3. Set Manage Settings to Allowed for that group, taking inherited Denied rules into account.
  4. Save the Joomla permissions and test with an account that belongs to the intended group.

Keep the scope narrow

For Manage Settings, grant only the capability required for that maintenance role. A technician who needs narrower access should receive the corresponding focused permission rather than broad component authority. Production push and production rollback are even stricter: current 1.01.14 requires a Joomla Super User with the required QCUL operation permission.

Defense-in-depth principle

Granting Manage Settings Permission is one layer in QCUL’s security model. Keep Joomla ACL, CSRF tokens, private gate/storage, laboratory identity, runtime authorization, side-effect quarantine, production Super User checks, and careful handling of production-derived evidence together rather than weakening another control to make one workflow more convenient.


Community Discussion

Want to compare update-testing workflows, share practical tips, or discuss how you use this QCUL feature? Visit the QC Update Laboratory Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.