Troubleshooting an Expired or Already-Used Handoff
Troubleshooting an Expired or Already-Used Handoff requires identifying whether the problem is in plugin visibility, target eligibility, the short-lived handoff, or the separate frontend session before changing configuration.
Diagnostic procedure
- Return to the original Joomla administrator tab.
- Do not refresh, copy, or reuse the failed handoff page/token.
- Start a new handoff for the exact target username.
- Complete the new-tab transition within the configured 30–300 second lifetime.
- If valid fresh handoffs fail immediately, inspect database writes to the QCUI token table and clock/time consistency.
Token rule for this error
QCUI accepts only an unused token whose expires_at has not passed, then atomically sets used_at. Refreshing or resubmitting the same handoff after one successful consume cannot work; create a new handoff.
Information to preserve
Record the configured token lifetime, approximate delay before consume, and whether the same handoff page was submitted/refreshed more than once. Never include the raw token.
When to escalate
If Troubleshooting an Expired or Already-Used Handoff persists after the documented layer is verified, stop creating repeated handoffs and preserve the exact error/context. A private support case should include version/state evidence but never passwords, session cookies, MFA secrets, or raw QCUI tokens.
Community Discussion
Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.