What Happens If the Issuing Administrator Loses Super User Authorization

What Happens If the Issuing Administrator Loses Super User Authorization explains the current QCUI 1.0.03 behavior and how it affects a Super User who needs to inspect the Joomla frontend as an eligible user.

Authorization is not frozen at issuance

A token row remembers the issuing administrator ID, not a permanent grant of that administrator’s old privileges. At consume time QCUI reloads that account and requires core.admin again.

If authority changed

QCUI records denied_admin and shows that the administrator authorization is no longer valid. Restore permissions only if appropriate, then create a new handoff. Do not attempt to reuse the old token.

Why this closes a race

Short token lifetimes reduce exposure, but revalidation additionally prevents a token from being used after the issuer’s trusted role has already been revoked.

Do not bypass Joomla account state

What Happens If the Issuing Administrator Loses Super User Authorization should be resolved through normal Joomla user/ACL administration. QCUI deliberately refuses to impersonate accounts that Joomla or QCUI currently considers unsafe/ineligible; changing database flags or handcrafting a token would remove the controls the support workflow depends on.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.