What QC User Impersonation Does

What QC User Impersonation Does explains the current QCUI 1.0.03 behavior and how it affects a Super User who needs to inspect the Joomla frontend as an eligible user.

Purpose

QC User Impersonation lets an authenticated Joomla Super User open the site frontend exactly as an eligible user without learning, changing, or storing that user’s password. The support session opens in a separate browser tab, so the original administrator tab stays available for configuration changes and comparison.

Core workflow

StageQCUI 1.0.03 behavior
Administrator startAn authenticated Joomla Super User submits the exact target username from the Impersonate User popup with Joomla CSRF protection.
One-time handoffQCUI creates a random 32-byte token, stores only its SHA-256 hash, and gives the raw 64-character hexadecimal token to the one-time handoff page.
Frontend consumeThe new frontend tab atomically marks the unused, unexpired token as used, then revalidates both administrator authority and target eligibility.
Identity switchQCUI forks the frontend session, loads the target identity, marks MFA satisfied for this explicit support session, and leaves the original administrator session separate.
EndThe impersonated tab is forked to a fresh guest identity. QCUI intentionally does not call the target user’s normal Joomla logout path.

What the user sees

The impersonated frontend displays a floating QCUI banner containing the target username and display name plus End impersonation. The banner can be dragged and its position is remembered in browser sessionStorage for that tab.

Best use

Use QCUI to reproduce menu/module visibility, ACL, profile, portal, membership, subscription, account-area, and other user-specific frontend behavior. Actions performed while impersonating are real frontend actions, so use the same care you would use while logged in as that customer.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.