What Happens After the QCUI Handoff Is Accepted
What Happens After the QCUI Handoff Is Accepted explains the current QCUI 1.0.03 behavior and how it affects a Super User who needs to inspect the Joomla frontend as an eligible user.
Successful consume
Once the token is claimed and both identities pass revalidation, QCUI loads the target as the site application identity, forks the Joomla frontend session, stores the target user in the new session, sets com_users.mfa_checked=1, updates session metadata, and marks the browser’s joomla_user_state as logged in.
QCUI markers
The same session stores qclau.impersonating, administrator ID, target ID and UTC start time. The frontend banner is rendered only while those flags and the actual active target identity agree.
Verify the result
- Frontend identity is the expected target.
- QCUI banner is visible.
- Administrator tab remains the original Super User session.
Session-safety check
After working with What Happens After the QCUI Handoff Is Accepted, verify the identities explicitly: the support frontend should show the expected target while active, End impersonation should make that frontend guest, and the original administrator tab should remain the authenticated Super User. Any result that collapses those identities together should be investigated before further use.
Community Discussion
Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.