What QC User Impersonation Does Not Do

What QC User Impersonation Does Not Do explains the current QCUI 1.0.03 behavior and how it affects a Super User who needs to inspect the Joomla frontend as an eligible user.

Deliberate boundaries

  • No universal/master password.
  • No password display, capture, reset, or storage.
  • No impersonation of Super User accounts.
  • No background or silent identity switching.
  • No operation while Joomla Shared Sessions is enabled.
  • No component dashboard, Scheduled Tasks, license key, entitlement tier, or preview system.
  • No normal target-user logout when ending the support session.

Why the boundaries matter

QCUI is a support/admin tool, not a second authentication system. Its security depends on an already authenticated Joomla Super User, a short-lived one-time handoff, strict target validation, and a separate frontend session. Expanding it into a master-password or unrestricted account-switching feature would remove the controls that make the current design safe.

Operational implication

If you need to test a Super User, a user intentionally denied frontend login, or a site configured with Shared Sessions, use a different authorized test method. Do not weaken those controls solely to force QCUI to accept an unsupported scenario.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.