How QCUL Protects Private Laboratory Storage
QCUL stores packages, checkpoints, manifests, evidence, and temporary operational artifacts under a protected private storage area rather than placing them in ordinary public content paths.
Private storage role
Current source uses a protected area under media/quantacade/qcul-private with run-scoped subdirectories for packages/checkpoints/evidence. QCUL creates restrictive filesystem/server-denial protections where supported.
Path validation
Laboratory runtime/install operations verify that package paths remain inside the allowed run-owned package vault before use. This prevents a signed lab-install call from being repurposed to install an arbitrary server file.
Operational care
- Do not move private QCUL artifacts into a public downloads directory.
- Maintain sufficient disk space/permissions for the protected directory.
- Let QCUL lifecycle cleanup remove owned temporary data.
- Treat a backup containing this directory as sensitive maintenance data.
Defense-in-depth principle
How QCUL Protects Private Laboratory Storage is one layer in QCUL’s security model. Keep Joomla ACL, CSRF tokens, private gate/storage, laboratory identity, runtime authorization, side-effect quarantine, production Super User checks, and careful handling of production-derived evidence together rather than weakening another control to make one workflow more convenient.
Community Discussion
Want to compare update-testing workflows, share practical tips, or discuss how you use this QCUL feature? Visit the QC Update Laboratory Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.