QC User Impersonation
Official QC User Impersonation documentation for secure frontend impersonation, eligibility and access controls, starting and ending sessions, support and ACL testing workflows, security safeguards, administration, and troubleshooting.
Subcategories
Install and configure QC User Impersonation 1.0.03, verify the System plugin, understand the free feature set and internal plugin identity, configure the handoff token lifetime, update safely, and establish a secure first-use workflow.
Use the Joomla administrator impersonation launcher, enter an exact username, start the secure handoff, open the impersonated frontend in a separate browser tab, and understand the one-time handoff page and launcher controls.
Understand which Joomla users can be impersonated, how QCUI validates Super User authorization and target eligibility, why certain accounts are refused, and how Shared Sessions and frontend login permission affect impersonation.
Work safely inside the separate impersonated frontend session, identify the active target account, use and reposition the QCUI banner, navigate normally, end impersonation cleanly, and switch between users without affecting unrelated sessions.
Use QCUI to reproduce customer issues and test Joomla menus, modules, access levels, restricted content, memberships, profiles, portals, forms, role-specific dashboards, extension workflows, user groups, and ACL changes.
Understand QCUI's security model, Super User enforcement, one-time token generation and hashing, expiration and replay prevention, CSRF protections, response headers, session forking, identity switching, MFA handling, and Shared Sessions restriction.
Understand QCUI audit events and stored evidence, protect customer information during support sessions, avoid password collection, coordinate support-team impersonation work, and follow safe operational practices from start through session completion.
Maintain QC User Impersonation through Joomla updates, understand enabled-state preservation and the retained qcloginasuser identity, review token and audit data tables, token cleanup and schema migrations, and uninstall or reinstall the plugin safely.
Troubleshoot missing launcher controls, disabled plugins, username and eligibility errors, Shared Sessions, invalid or expired handoffs, authorization changes, frontend-session problems, missing banners, CSRF errors, and unexpected session behavior.
Reference QCUI 1.0.03 settings, eligibility rules, audit events, data tables, request lifecycle, browser and session boundaries, supported scenarios, current product limits, support-information requirements, and safe-support best practices.