Why the Target User Is Revalidated at Consumption Time
Why the Target User Is Revalidated at Consumption Time is a deliberate QCUI 1.0.03 behavior that protects administrator access, target-account safety, or the integrity of the one-time impersonation handoff.
Revalidation closes the gap
Token issuance records administrator and target IDs, but it does not freeze their authorization/account state. At consume time QCUI reloads both Joomla users.
Administrator check
The issuer must still authorize core.admin; otherwise QCUI writes denied_admin and refuses the handoff.
Target check
The target is again checked for existence, self-match, block, password reset requirement, Super User status, and core.login.site. This prevents a short-lived token from bypassing a security change made after issuance.
Security boundary
The controls described for Why the Target User Is Revalidated at Consumption Time are complementary. Super-User authorization does not make a reusable token safe; a one-time token does not make Shared Sessions safe; and a visible banner does not make state-changing customer actions harmless. Preserve the complete 1.0.03 security model rather than removing individual checks for convenience.
Security boundary
The controls described for Why the Target User Is Revalidated at Consumption Time are complementary. Super-User authorization does not make a reusable token safe; a one-time token does not make Shared Sessions safe; and a visible banner does not make state-changing customer actions harmless. Preserve the complete 1.0.03 security model rather than removing individual checks for convenience.
Community Discussion
Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.