What Information QCUI Stores in Its Audit Records
What Information QCUI Stores in Its Audit Records explains the current QCUI 1.0.03 behavior and how it affects a Super User who needs to inspect the Joomla frontend as an eligible user.
| Data | Lifecycle |
|---|---|
| Handoff token row | Stores hash, admin/target IDs, created/expires timestamps and used timestamp. Expired rows older than 24 hours are opportunistically cleaned when a new handoff is issued. |
| Audit row | Stores action, administrator ID, target ID, UTC creation time, IP address, user agent and a short details field. |
| Frontend session flags | Stored only in the impersonated Joomla session and cleared when ending or when the active identity no longer matches the expected target. |
| Banner position | Stored in browser sessionStorage for the current tab/session; it is not a server-side preference. |
Audit field sizes
Audit records use action up to 32 characters, administrator/target IDs, UTC datetime, IP address up to 45 characters, user agent up to 255 characters, and details up to 255 characters.
Not stored
QCUI does not store target passwords, MFA secrets, or a reusable master credential. The raw handoff token is not persisted; only its SHA-256 hash is stored.
Community Discussion
Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.