How QCUI Cleans Up Old Expired Handoff Tokens

How QCUI Cleans Up Old Expired Handoff Tokens describes a current QCUI 1.0.03 implementation detail that matters when you are validating security, session isolation, or support behavior.

Opportunistic cleanup

Before issuing a new handoff, QCUI deletes token rows whose expires_at is older than the current UTC time minus 86,400 seconds (24 hours).

Important distinction

A token becomes unusable as soon as its short 30–300 second expiry passes. Keeping the expired row for up to roughly another day is database housekeeping, not an extension of its validity.

No Scheduled Task

This cleanup runs as part of handoff issuance. QCUI registers no Joomla Scheduled Task solely for token maintenance.

Maintenance boundary

How QCUI Cleans Up Old Expired Handoff Tokens should be handled through Joomla’s extension installer/update lifecycle. The retained qcloginasuser identity, schema migrations, and uninstall SQL exist to make that lifecycle predictable; manual file/table surgery can create a state the released plugin was not designed to manage.

Maintenance boundary

How QCUI Cleans Up Old Expired Handoff Tokens should be handled through Joomla’s extension installer/update lifecycle. The retained qcloginasuser identity, schema migrations, and uninstall SQL exist to make that lifecycle predictable; manual file/table surgery can create a state the released plugin was not designed to manage.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.