Why QCUI Removes Old Session Metadata When Switching Identities

Why QCUI Removes Old Session Metadata When Switching Identities is a deliberate QCUI 1.0.03 behavior that protects administrator access, target-account safety, or the integrity of the one-time impersonation handoff.

Cleanup after a fork

QCUI remembers the pre-fork session ID and attempts to delete that row from Joomla’s #__session table after the new identity/session is established. If the session handler already removed it or cleanup fails, QCUI treats that cleanup as non-fatal.

Why it is narrow

The query targets only the old session ID from this identity switch. It is not a bulk “log target user out everywhere” operation.

Operational note

If session metadata behaves unexpectedly, investigate the configured Joomla session handler, custom SSO/security plugins, and Shared Sessions rather than manually deleting unrelated sessions.

Security boundary

The controls described for Why QCUI Removes Old Session Metadata When Switching Identities are complementary. Super-User authorization does not make a reusable token safe; a one-time token does not make Shared Sessions safe; and a visible banner does not make state-changing customer actions harmless. Preserve the complete 1.0.03 security model rather than removing individual checks for convenience.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.