Impersonating an Ordinary Enabled Frontend User
Impersonating an Ordinary Enabled Frontend User explains the current QCUI 1.0.03 behavior and how it affects a Super User who needs to inspect the Joomla frontend as an eligible user.
Eligible baseline
The typical QCUI target is an enabled, non-Super-User Joomla account that is not waiting for a password reset and is authorized for core.login.site.
Test procedure
- Confirm the account in Users → Manage.
- Start QCUI from a Super User administrator tab using the exact username.
- Verify the new frontend tab identifies the target.
- Navigate to one user-specific area, then end impersonation.
What QCUI does not require
You do not need the target’s password or MFA response. This is an explicit Super-User support session; QCUI marks MFA as satisfied inside the forked support session after all impersonation checks pass.
Do not bypass Joomla account state
Impersonating an Ordinary Enabled Frontend User should be resolved through normal Joomla user/ACL administration. QCUI deliberately refuses to impersonate accounts that Joomla or QCUI currently considers unsafe/ineligible; changing database flags or handcrafting a token would remove the controls the support workflow depends on.
Community Discussion
Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.