How QCUI Avoids Collecting or Changing User Passwords

How QCUI Avoids Collecting or Changing User Passwords describes a current QCUI 1.0.03 implementation detail that matters when you are validating security, session isolation, or support behavior.

No customer credential exchange

QCUI targets a user by exact Joomla username after the support administrator is already authenticated as a Super User. It never asks for the target password, does not reset it, and does not store it.

Support advantage

This removes a common bad support pattern: asking customers to disclose passwords or setting a temporary password that changes their account security state.

What replaces the password

Authorization comes from the issuing Super User plus a random, short-lived one-time handoff token and strict eligibility revalidation. That token is not a universal password and cannot impersonate privileged/ineligible accounts.

Privacy boundary

For How QCUI Avoids Collecting or Changing User Passwords, QCUI’s audit/session evidence should be handled as support/security data. Store or share only what your organization actually needs, keep raw handoff secrets out of tickets, and avoid copying unrelated customer information simply because the impersonated account can display it.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.