User Impersonation
User Impersonation Plugin for Forma LMS
1. Introduction
The User Impersonation plugin for Forma LMS allows authorized administrators to temporarily access the platform as another user.
The plugin is intended for support and debugging activities: an administrator can verify what a specific user sees in the LMS, reproduce access issues, and check course visibility or navigation problems without asking for the user's credentials.
During impersonation, the platform shows a visible banner and prevents learning tracking from being written as the impersonated user.
2. Installation and Activation
When activated, the plugin registers:
3. Plugin Configuration
No external API credentials are required.
After activation, access depends on the administrator level and on the standard Forma LMS visibility rules:
The plugin requires Forma LMS 4.2 or later.
4. User Impersonation from User Management
4.1 Starting an Impersonation Session
Within the user management area:
After confirmation, Forma LMS switches the current session to the selected user and redirects the administrator to the LMS area.
The administrator can then navigate the platform with the same visibility and permissions as the selected user.
5. Active Impersonation Session
While impersonation is active, Forma LMS displays a red banner across the interface.
During the session, the plugin:
6. Stopping Impersonation
To return to the original administrator session:
The stop action is protected by a token and the session ID is regenerated when impersonation starts and stops.
If the session expires while impersonation is active, the plugin writes a timeout entry in the audit log.
7. Reports and History
The plugin provides an Impersonation Log page for super administrators.
The log shows:
The log can be filtered by administrator and by impersonated user.
8. Security Notes
The plugin is designed for support and troubleshooting, not for normal user activity.
Main safeguards: