QCUI Start, Consume, and End Request Lifecycle
QCUI Start, Consume, and End Request Lifecycle summarizes the current QCUI 1.0.03 rules and operational boundaries that are useful during administration and support.
| Stage | QCUI 1.0.03 behavior |
|---|---|
| Administrator start | An authenticated Joomla Super User submits the exact target username from the Impersonate User popup with Joomla CSRF protection. |
| One-time handoff | QCUI creates a random 32-byte token, stores only its SHA-256 hash, and gives the raw 64-character hexadecimal token to the one-time handoff page. |
| Frontend consume | The new frontend tab atomically marks the unused, unexpired token as used, then revalidates both administrator authority and target eligibility. |
| Identity switch | QCUI forks the frontend session, loads the target identity, marks MFA satisfied for this explicit support session, and leaves the original administrator session separate. |
| End | The impersonated tab is forked to a fresh guest identity. QCUI intentionally does not call the target user’s normal Joomla logout path. |
Request methods
QCUI handles explicit POST actions named start in Administrator and consume/end on Site. Ordinary GET requests do not trigger an identity switch.
Error behavior
Start denials return the administrator to Joomla Users; frontend consume/end errors redirect to the site root with Joomla messages. The raw handoff page is deliberately minimal/transient.
Community Discussion
Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.