Why QCUI Checks Target Eligibility Again When the Handoff Is Consumed

Why QCUI Checks Target Eligibility Again When the Handoff Is Consumed is a deliberate QCUI 1.0.03 behavior that protects administrator access, target-account safety, or the integrity of the one-time impersonation handoff.

Consume-time revalidation

After the token is atomically claimed, QCUI reloads both the issuing administrator and target from Joomla. It confirms the issuer is still a Super User and calls the same target-validation rules again before switching identity.

Changes that can stop an already-issued handoff

  • Issuer loses Super User permission.
  • Target becomes blocked.
  • Target is changed to require password reset.
  • Target becomes a Super User.
  • Target loses frontend login permission.
  • Joomla Shared Sessions is enabled before consume.

Result

The new tab returns to the site root with an explicit error and records the relevant denial event. Issue a fresh handoff only after the current account state is intentionally valid.

Do not bypass Joomla account state

Why QCUI Checks Target Eligibility Again When the Handoff Is Consumed should be resolved through normal Joomla user/ACL administration. QCUI deliberately refuses to impersonate accounts that Joomla or QCUI currently considers unsafe/ineligible; changing database flags or handcrafting a token would remove the controls the support workflow depends on.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.