How QCUI Uses Joomla CSRF Protection for Start and End Actions
How QCUI Uses Joomla CSRF Protection for Start and End Actions describes a current QCUI 1.0.03 implementation detail that matters when you are validating security, session isolation, or support behavior.
Protected actions
Administrator start and frontend end requests include Joomla’s form token and call checkToken('post'). An invalid start token is denied; an invalid end token leaves the session unchanged and reports an error.
Consume is different
The one-time consume form is authenticated by the unpredictable one-time QCUI token itself rather than a Joomla form token inherited from the administrator session. That raw token is short-lived, hash-verified, single-use, and then followed by administrator/target revalidation.
Do not script around these checks
Use the supplied launcher/handoff/banner actions so Joomla and QCUI can enforce the correct request protections.
Security boundary
The controls described for How QCUI Uses Joomla CSRF Protection for Start and End Actions are complementary. Super-User authorization does not make a reusable token safe; a one-time token does not make Shared Sessions safe; and a visible banner does not make state-changing customer actions harmless. Preserve the complete 1.0.03 security model rather than removing individual checks for convenience.
Community Discussion
Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.