Why Users Without Frontend Login Permission Cannot Be Impersonated
Why Users Without Frontend Login Permission Cannot Be Impersonated is a deliberate QCUI 1.0.03 behavior that protects administrator access, target-account safety, or the integrity of the one-time impersonation handoff.
Current rule
QCUI requires Joomla authorization for core.login.site.
Security reason
If frontend login is intentionally denied, the target is intentionally outside QCUI’s supported support-session model.
Verification
Trace the target’s effective user groups and core.login.site result; change ACL only when the user is genuinely supposed to sign in to the frontend.
Do not bypass Joomla account state
Why Users Without Frontend Login Permission Cannot Be Impersonated should be resolved through normal Joomla user/ACL administration. QCUI deliberately refuses to impersonate accounts that Joomla or QCUI currently considers unsafe/ineligible; changing database flags or handcrafting a token would remove the controls the support workflow depends on.
Do not bypass Joomla account state
Why Users Without Frontend Login Permission Cannot Be Impersonated should be resolved through normal Joomla user/ACL administration. QCUI deliberately refuses to impersonate accounts that Joomla or QCUI currently considers unsafe/ineligible; changing database flags or handcrafting a token would remove the controls the support workflow depends on.
Community Discussion
Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.