Understanding the QCUI One-Time Token Database Table

Understanding the QCUI One-Time Token Database Table explains the current QCUI 1.0.03 behavior and how it affects a Super User who needs to inspect the Joomla frontend as an eligible user.

Table purpose

#__qcloginasuser_tokens temporarily coordinates a one-time administrator-to-frontend handoff without storing the target password.

ColumnPurpose
token_hashUnique SHA-256 digest of the raw handoff token.
admin_user_id / target_user_idLinks the one-time authorization to issuer and requested target.
created_at / expires_atDefines creation and short validity window in UTC.
used_atNULL until the token is atomically claimed; then records consumption time.

Indexes and cleanup

The hash is unique; expiry and target are indexed. Old expired rows more than 24 hours past expiry are opportunistically deleted when a new token is issued.

Maintenance boundary

Understanding the QCUI One-Time Token Database Table should be handled through Joomla’s extension installer/update lifecycle. The retained qcloginasuser identity, schema migrations, and uninstall SQL exist to make that lifecycle predictable; manual file/table surgery can create a state the released plugin was not designed to manage.

Maintenance boundary

Understanding the QCUI One-Time Token Database Table should be handled through Joomla’s extension installer/update lifecycle. The retained qcloginasuser identity, schema migrations, and uninstall SQL exist to make that lifecycle predictable; manual file/table surgery can create a state the released plugin was not designed to manage.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.