How QCUI Generates the Random One-Time Handoff Secret

How QCUI Generates the Random One-Time Handoff Secret describes a current QCUI 1.0.03 implementation detail that matters when you are validating security, session isolation, or support behavior.

Generation

QCUI calls PHP random_bytes(32) and converts those 32 random bytes to hexadecimal. The result is a 64-character token suitable for the one-time handoff form.

Storage

Before inserting the token row, QCUI computes SHA-256 and stores the 64-character hash, not the raw token. The raw secret exists only in the handoff response sent to the authorized administrator’s new tab.

Scope

The token identifies the issuing administrator and target IDs plus creation/expiration time. It is not a reusable login credential and does not contain the user’s password.

Security boundary

The controls described for How QCUI Generates the Random One-Time Handoff Secret are complementary. Super-User authorization does not make a reusable token safe; a one-time token does not make Shared Sessions safe; and a visible banner does not make state-changing customer actions harmless. Preserve the complete 1.0.03 security model rather than removing individual checks for convenience.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.