Granting Remove Laboratories Permission

The Remove Laboratories Joomla ACL action lets you delegate one defined QCUL capability without automatically granting every laboratory or production operation.

What this permission controls

Remove Laboratories allows an authorized Joomla user group to permanently remove a laboratory and its associated temporary rollback checkpoints. QCUL checks permissions server-side; hiding or showing a button is not the security boundary.

Grant it through Joomla ACL

  1. Open System → Global Configuration or the QC Update Laboratory component permissions screen, depending on how you manage component ACL.
  2. Choose the Joomla user group that should receive the capability.
  3. Set Remove Laboratories to Allowed for that group, taking inherited Denied rules into account.
  4. Save the Joomla permissions and test with an account that belongs to the intended group.

Keep the scope narrow

For Remove Laboratories, grant only the capability required for that maintenance role. A technician who needs narrower access should receive the corresponding focused permission rather than broad component authority. Production push and production rollback are even stricter: current 1.01.14 requires a Joomla Super User with the required QCUL operation permission.

Defense-in-depth principle

Granting Remove Laboratories Permission is one layer in QCUL’s security model. Keep Joomla ACL, CSRF tokens, private gate/storage, laboratory identity, runtime authorization, side-effect quarantine, production Super User checks, and careful handling of production-derived evidence together rather than weakening another control to make one workflow more convenient.


Community Discussion

Want to compare update-testing workflows, share practical tips, or discuss how you use this QCUL feature? Visit the QC Update Laboratory Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.