QCUI Start, Consume, and End Request Lifecycle

QCUI Start, Consume, and End Request Lifecycle summarizes the current QCUI 1.0.03 rules and operational boundaries that are useful during administration and support.

StageQCUI 1.0.03 behavior
Administrator startAn authenticated Joomla Super User submits the exact target username from the Impersonate User popup with Joomla CSRF protection.
One-time handoffQCUI creates a random 32-byte token, stores only its SHA-256 hash, and gives the raw 64-character hexadecimal token to the one-time handoff page.
Frontend consumeThe new frontend tab atomically marks the unused, unexpired token as used, then revalidates both administrator authority and target eligibility.
Identity switchQCUI forks the frontend session, loads the target identity, marks MFA satisfied for this explicit support session, and leaves the original administrator session separate.
EndThe impersonated tab is forked to a fresh guest identity. QCUI intentionally does not call the target user’s normal Joomla logout path.

Request methods

QCUI handles explicit POST actions named start in Administrator and consume/end on Site. Ordinary GET requests do not trigger an identity switch.

Error behavior

Start denials return the administrator to Joomla Users; frontend consume/end errors redirect to the site root with Joomla messages. The raw handoff page is deliberately minimal/transient.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.