Understanding the QCUI One-Time Token Database Table
Understanding the QCUI One-Time Token Database Table explains the current QCUI 1.0.03 behavior and how it affects a Super User who needs to inspect the Joomla frontend as an eligible user.
Table purpose
#__qcloginasuser_tokens temporarily coordinates a one-time administrator-to-frontend handoff without storing the target password.
| Column | Purpose |
|---|---|
| token_hash | Unique SHA-256 digest of the raw handoff token. |
| admin_user_id / target_user_id | Links the one-time authorization to issuer and requested target. |
| created_at / expires_at | Defines creation and short validity window in UTC. |
| used_at | NULL until the token is atomically claimed; then records consumption time. |
Indexes and cleanup
The hash is unique; expiry and target are indexed. Old expired rows more than 24 hours past expiry are opportunistically deleted when a new token is issued.
Maintenance boundary
Understanding the QCUI One-Time Token Database Table should be handled through Joomla’s extension installer/update lifecycle. The retained qcloginasuser identity, schema migrations, and uninstall SQL exist to make that lifecycle predictable; manual file/table surgery can create a state the released plugin was not designed to manage.
Maintenance boundary
Understanding the QCUI One-Time Token Database Table should be handled through Joomla’s extension installer/update lifecycle. The retained qcloginasuser identity, schema migrations, and uninstall SQL exist to make that lifecycle predictable; manual file/table surgery can create a state the released plugin was not designed to manage.
Community Discussion
Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.