What Happens If the Target Account Changes Before the Handoff Is Consumed

What Happens If the Target Account Changes Before the Handoff Is Consumed explains the current QCUI 1.0.03 behavior and how it affects a Super User who needs to inspect the Joomla frontend as an eligible user.

Consume-time revalidation

After the token is atomically claimed, QCUI reloads both the issuing administrator and target from Joomla. It confirms the issuer is still a Super User and calls the same target-validation rules again before switching identity.

Changes that can stop an already-issued handoff

  • Issuer loses Super User permission.
  • Target becomes blocked.
  • Target is changed to require password reset.
  • Target becomes a Super User.
  • Target loses frontend login permission.
  • Joomla Shared Sessions is enabled before consume.

Result

The new tab returns to the site root with an explicit error and records the relevant denial event. Issue a fresh handoff only after the current account state is intentionally valid.

Do not bypass Joomla account state

What Happens If the Target Account Changes Before the Handoff Is Consumed should be resolved through normal Joomla user/ACL administration. QCUI deliberately refuses to impersonate accounts that Joomla or QCUI currently considers unsafe/ineligible; changing database flags or handcrafting a token would remove the controls the support workflow depends on.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.