QC Frontend User Manager Current Terminology and Version-2.0.4 Corrections
Define current terms such as frontend manager, User Type Profile, Invite Pack, Invite Link, Join Code, Base/Effective tier, Authorized Domain, approval request, temporary access, and unified dashboard; explicitly retire old license-key/3-day-preview/daily-revalidation wording.
This guide follows the accepted QC Frontend User Manager 2.0.4 implementation and applies to All plans; reference. QCFUM delegates selected Joomla user-onboarding and management workflows without making frontend staff Joomla backend administrators. When older manuals or walkthrough wording differs from the current source or accepted keyless-entitlement behavior, the current implementation takes precedence.
Before You Begin
- Take a current Joomla/site backup before installation, upgrade, or structural changes.
- Confirm Administrator access and permission to install extensions and inspect Scheduled Tasks.
- Record the current QCFUM version and Base/Effective tier before entitlement or task changes.
Step-by-Step Workflow
- Open Invitations in the unified QCFUM Dashboard.
- Choose the appropriate Invite Pack/Profile workflow and enter the recipient information.
- Review expiration, approval, landing, and email behavior inherited from the Pack.
- Create/send the Invite Link and confirm the new record appears in invitation history/Tracker.
- If the workflow requires approval, process it through the authorized Approval Queue before expecting a usable setup link.
- Test completion with the recipient flow and confirm the resulting Joomla account/group state.
Unified Frontend Dashboard
| Tab | Current role |
|---|---|
| Users | Max / All Access and permission-dependent delegated Joomla user management. |
| Create User | Direct user creation; Max can expose the Join Code sub-workflow where enabled. |
| Invitations | Create, track, nudge/resend, and cancel Invite Links. |
| Import | Pro+ CSV preview and processing. |
| Recent Users | Basic+ recently created account history. |
| Tracker | Basic+ combined onboarding history for created users and Invite Links. |
| Approval Queue | Pro+ review when approval workflows and permission allow it. |
The visible tab set is intentionally dynamic. A tab can be absent because of plan entitlement, QCFUM ACL, configuration, or the current account—not because the unified Dashboard is incomplete.
Server-Side Safeguards
- Joomla menu access, QCFUM ACL, product entitlement, and target-specific authorization are separate gates.
- Super Users and equivalent protected administrative accounts remain protected server-side.
- Visibility does not automatically imply editability; a user may be shown but intentionally view-only.
- Allowed destination groups are constrained independently from the groups a target user currently has.
- Bulk actions re-authorize each selected target server-side; the UI selection is never the security boundary.
- Password resets are delivered privately; frontend managers do not receive the generated password.
- The QCFUM MFA Required value is an administrative flag only, not Joomla MFA enforcement.
Join-Code Eligibility
- Effective Max/All Access is required for the current Join Code feature.
- The Join Code itself must be published, within its allowed time window, and below its use limit.
- Its linked Invite Pack and User Type Profile must remain valid for the current onboarding request.
- Usage reservation is handled atomically so concurrent requests cannot legitimately exceed the final available use.
Durable Approval Model
- Approval is a stored workflow decision, not merely a hidden frontend button.
- The reviewer must still have permission when acting on the pending request.
- The protected action is revalidated at approval time so changed groups, target protections, or entitlement cannot be bypassed by an old request.
- Downgrade or entitlement change does not justify silently deleting durable pending security decisions; availability and final authorization remain current-state dependent.
Define current terms such as frontend manager, User Type
Define current terms such as frontend manager, User Type Profile, Invite Pack, Invite Link, Join Code, Base/Effective tier, Authorized Domain, approval request, temporary access, and unified dashboard. In QCFUM 2.0.4, this must be evaluated together with the current Effective tier, the Joomla/QCFUM permissions of the acting account, and target/workflow safeguards. QCFUM is designed to fail closed around protected users and sensitive actions rather than trusting the presence of a frontend button as authorization.
For QC Frontend User Manager Current Terminology and Version-2.0.4 Corrections, test the exact workflow with a safe non-administrator account and a deliberately chosen target. QCFUM’s frontend presentation is not the authorization boundary: a control can be visible while the server still refuses an unsafe target, an unavailable tier, an invalid workflow state, or a group change that violates administrator-defined safeguards.
Explicitly retire old license-key/3-day-preview/daily-revalidation wording
explicitly retire old license-key/3-day-preview/daily-revalidation wording. In QCFUM 2.0.4, this must be evaluated together with the current Effective tier, the Joomla/QCFUM permissions of the acting account, and target/workflow safeguards. QCFUM is designed to fail closed around protected users and sensitive actions rather than trusting the presence of a frontend button as authorization.
For QC Frontend User Manager Current Terminology and Version-2.0.4 Corrections, test the exact workflow with a safe non-administrator account and a deliberately chosen target. QCFUM’s frontend presentation is not the authorization boundary: a control can be visible while the server still refuses an unsafe target, an unavailable tier, an invalid workflow state, or a group change that violates administrator-defined safeguards.
How This Fits into QCFUM
This category establishes the installation, entitlement, update, and administrative foundation. It should be completed before delegating frontend onboarding to staff.
A reliable QCFUM configuration keeps Joomla authoritative for real user accounts while QCFUM owns the delegated workflow, attribution, approval, automation, and safety rules around those accounts. This separation matters during upgrades and downgrades: preserving QCFUM records does not mean every preserved premium feature remains usable at a lower Effective tier.
Security and Data-Protection Notes
- Use least privilege for menu access and QCFUM ACL; grant staff only the actions required for their role.
- Never share passwords, invite tokens, API credentials, or private account data in screenshots, support requests, or custom email content.
- Treat Super Users and equivalent administrative-capability accounts as protected even when a UI configuration appears permissive.
- Verify destructive or access-changing actions with a safe test account before enabling them for production staff.
- Remember that uninstall/reinstall is not a supported method for wiping QCFUM business data or resetting entitlement/preview history.
Verify the Result
- Status shows the expected Base and Effective tiers for the current Authorized Domain.
- Entitlement Revalidation is healthy at the canonical hourly cadence unless this guide is specifically diagnosing that task.
- The resulting Joomla user/group state matches the intended QCFUM workflow.
- A protected or out-of-scope user remains protected when tested with the delegated staff account.
- Invitation status, expiration/approval state, Pack/Profile mapping, and delivery status are consistent.
- Published/expiration/use-limit and linked Pack/Profile state are all valid for an intended successful test.
- The relevant Joomla Scheduled Task is published/healthy and security expiration behavior is not accidentally disabled with commercial automation.
Common Mistakes to Avoid
- Treating invitation status/delivery as equivalent to a permanently reusable plaintext token.
- Publishing a reusable Join Code without a sensible expiration/use limit or without validating the linked Pack/Profile.
- Assuming an old pending approval guarantees the action can still run after groups, protections, or entitlement change.
- Disabling the Scheduled Automation task while existing temporary-access users still depend on expiration enforcement.
- Testing only as Super User instead of the actual delegated staff group.
- Changing multiple security/workflow settings at once during troubleshooting, making the real cause difficult to identify.
Troubleshooting
- If a control or tab is missing, check Effective tier, QCFUM ACL, menu access, and feature configuration before assuming installation damage.
- If a user cannot be selected or changed, check protected groups/IDs, core administrative protection, visibility/editability rules, destination-group rules, and the delegated manager’s exact permissions.
- If onboarding stalls, inspect the stored workflow status (invite, approval, import, temporary access) rather than deleting the record and starting over immediately.
- If automation does not run, verify Joomla Scheduled Tasks and distinguish the hourly Entitlement Revalidation task from the separately configured Scheduled Automation task.
- If email does not arrive, verify Joomla mail transport independently, then inspect QCFUM template publication, recipient/address, queue state, and retry eligibility.
Operational Best Practice
Keep onboarding definitions simple enough that staff can select the correct Profile/Pack without guessing. Test every delegated workflow with the real staff Joomla group, keep entitlement/tasks healthy, and preserve an Administrator recovery path. When changing user-management safeguards, verify both a target that should be allowed and a protected target that must still be refused.
Community Discussion
Want to compare Joomla user-onboarding workflows, share practical QCFUM tips, or discuss how other administrators use this feature? Visit the QC Frontend User Manager Community. For private support, bug reports, account-specific entitlement problems, or feature requests, use the QuantaCade support system.