QC Update Laboratory Security Model Overview

QCUL’s security model assumes the laboratory contains production-derived sensitive data and that production push/rollback are high-impact operations, so it layers Joomla ACL, CSRF protection, private storage, gated lab access, runtime identity, signed operations, and side-effect quarantine.

Primary security layers

LayerProtection
Joomla ACLFocused permissions for settings, create/operate/view/remove laboratories, and reports; production push/rollback add Super User requirements.
Request integrityState-changing actions use POST plus Joomla form tokens and server-side reload of current run/item/state.
Private lab gateStrong run-specific access code and HttpOnly SameSite=Strict path-scoped cookie before Joomla where supported.
Private storageQCUL packages/checkpoints/evidence use protected run-scoped storage with server-denial protections.
Runtime authorizationLab installation/evidence endpoints require signed/expected runtime authorization rather than accepting arbitrary package paths.
Isolation/quarantineMail, Scheduler/lazy activity, sessions/remember-me, indexing, production URL references, and production-control actions are constrained in the clone.

Security is not data sanitization

The laboratory can still contain real production records. Treat its URL, access code, reports, screenshots, and stored evidence as sensitive; the private gate is the confidentiality boundary, while robots/noindex controls are only indexing defenses.

Defense-in-depth principle

QC Update Laboratory Security Model Overview is one layer in QCUL’s security model. Keep Joomla ACL, CSRF tokens, private gate/storage, laboratory identity, runtime authorization, side-effect quarantine, production Super User checks, and careful handling of production-derived evidence together rather than weakening another control to make one workflow more convenient.


Community Discussion

Want to compare update-testing workflows, share practical tips, or discuss how you use this QCUL feature? Visit the QC Update Laboratory Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.