Why Only Joomla Super Users See the Impersonate User Control

Why Only Joomla Super Users See the Impersonate User Control is a deliberate QCUI 1.0.03 behavior that protects administrator access, target-account safety, or the integrity of the one-time impersonation handoff.

Authorization rule

QCUI considers a user a Super User when Joomla authorizes core.admin. That check is performed before the launcher is injected and again when a handoff is started.

  • Super-User-only initiation: QCUI requires Joomla core.admin on the issuing identity.
  • Shared Sessions refusal: QCUI stops rather than risk replacing the administrator identity when Joomla is configured to share site/admin sessions.
  • Short-lived one-time token: configurable 30–300 seconds, 60 seconds by default, with atomic single-use consumption.
  • Hashed-at-rest secret: only the SHA-256 token hash is stored in the database.
  • Double validation: administrator authority and target eligibility are checked again at consumption time.
  • CSRF and cache controls: start/end actions use Joomla tokens; handoff responses are no-store/no-cache with a no-referrer policy.
  • Session isolation: the frontend session is forked instead of replacing the existing administrator session.

Why narrower is safer

Impersonation can expose whatever the target can see and can perform real frontend actions as that account. Restricting initiation to Joomla’s highest trusted administrative permission keeps the capability inside the site’s existing security model instead of inventing a second QCUI-specific support role.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.