What Happens to the Frontend Session When Impersonation Ends
What Happens to the Frontend Session When Impersonation Ends explains the current QCUI 1.0.03 behavior and how it affects a Super User who needs to inspect the Joomla frontend as an eligible user.
Procedure
- In the impersonated frontend tab, locate the QCUI banner.
- Confirm the banner identifies the expected username/display name.
- Click End impersonation.
- QCUI validates the Joomla CSRF token, forks the session to a guest identity, clears impersonation flags, and redirects to the site root.
- Verify the frontend tab is now guest while the original administrator tab is still signed in.
Implementation boundary
QCUI does not call Joomla’s normal logout for the target. It forks the current frontend session again, loads a guest identity, resets the MFA marker, clears QCUI flags, removes the old session metadata row when possible, and clears the Joomla user-state cookie.
Verify the result
- Frontend now behaves as guest.
- Target’s unrelated sessions remain intact.
- Administrator tab remains signed in.
Session-safety check
After working with What Happens to the Frontend Session When Impersonation Ends, verify the identities explicitly: the support frontend should show the expected target while active, End impersonation should make that frontend guest, and the original administrator tab should remain the authenticated Super User. Any result that collapses those identities together should be investigated before further use.
Community Discussion
Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.