What Information QCUI Stores in Its Audit Records

What Information QCUI Stores in Its Audit Records explains the current QCUI 1.0.03 behavior and how it affects a Super User who needs to inspect the Joomla frontend as an eligible user.

DataLifecycle
Handoff token rowStores hash, admin/target IDs, created/expires timestamps and used timestamp. Expired rows older than 24 hours are opportunistically cleaned when a new handoff is issued.
Audit rowStores action, administrator ID, target ID, UTC creation time, IP address, user agent and a short details field.
Frontend session flagsStored only in the impersonated Joomla session and cleared when ending or when the active identity no longer matches the expected target.
Banner positionStored in browser sessionStorage for the current tab/session; it is not a server-side preference.

Audit field sizes

Audit records use action up to 32 characters, administrator/target IDs, UTC datetime, IP address up to 45 characters, user agent up to 255 characters, and details up to 255 characters.

Not stored

QCUI does not store target passwords, MFA secrets, or a reusable master credential. The raw handoff token is not persisted; only its SHA-256 hash is stored.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.