Why Password-Reset-Required Users Cannot Be Impersonated

Why Password-Reset-Required Users Cannot Be Impersonated is a deliberate QCUI 1.0.03 behavior that protects administrator access, target-account safety, or the integrity of the one-time impersonation handoff.

Current rule

QCUI rejects accounts whose requireReset flag is set.

Security reason

Complete or administratively resolve the reset requirement; do not use impersonation to bypass a forced credential workflow.

Verification

Resolve the required password reset through Joomla’s normal user-security workflow first, then confirm requireReset is clear before creating a new handoff.

Do not bypass Joomla account state

Why Password-Reset-Required Users Cannot Be Impersonated should be resolved through normal Joomla user/ACL administration. QCUI deliberately refuses to impersonate accounts that Joomla or QCUI currently considers unsafe/ineligible; changing database flags or handcrafting a token would remove the controls the support workflow depends on.

Do not bypass Joomla account state

Why Password-Reset-Required Users Cannot Be Impersonated should be resolved through normal Joomla user/ACL administration. QCUI deliberately refuses to impersonate accounts that Joomla or QCUI currently considers unsafe/ineligible; changing database flags or handcrafting a token would remove the controls the support workflow depends on.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.