QC Update Laboratory Security Model Overview
QCUL’s security model assumes the laboratory contains production-derived sensitive data and that production push/rollback are high-impact operations, so it layers Joomla ACL, CSRF protection, private storage, gated lab access, runtime identity, signed operations, and side-effect quarantine.
Primary security layers
| Layer | Protection |
|---|---|
| Joomla ACL | Focused permissions for settings, create/operate/view/remove laboratories, and reports; production push/rollback add Super User requirements. |
| Request integrity | State-changing actions use POST plus Joomla form tokens and server-side reload of current run/item/state. |
| Private lab gate | Strong run-specific access code and HttpOnly SameSite=Strict path-scoped cookie before Joomla where supported. |
| Private storage | QCUL packages/checkpoints/evidence use protected run-scoped storage with server-denial protections. |
| Runtime authorization | Lab installation/evidence endpoints require signed/expected runtime authorization rather than accepting arbitrary package paths. |
| Isolation/quarantine | Mail, Scheduler/lazy activity, sessions/remember-me, indexing, production URL references, and production-control actions are constrained in the clone. |
Security is not data sanitization
The laboratory can still contain real production records. Treat its URL, access code, reports, screenshots, and stored evidence as sensitive; the private gate is the confidentiality boundary, while robots/noindex controls are only indexing defenses.
Defense-in-depth principle
QC Update Laboratory Security Model Overview is one layer in QCUL’s security model. Keep Joomla ACL, CSRF tokens, private gate/storage, laboratory identity, runtime authorization, side-effect quarantine, production Super User checks, and careful handling of production-derived evidence together rather than weakening another control to make one workflow more convenient.
Community Discussion
Want to compare update-testing workflows, share practical tips, or discuss how you use this QCUL feature? Visit the QC Update Laboratory Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.