<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Qlik reporting service and vizlib in Data Movement &amp; Streaming</title>
    <link>https://community.qlik.com/t5/Data-Movement-Streaming/Qlik-reporting-service-and-vizlib/m-p/2553360#M3689</link>
    <description>&lt;P&gt;If memory serves, some Vizlib Library objects work in NPrinting (Table works, iirc, and I think Pivot Table does too). I would strongly suggest taking this up with Vizlib Support directly, though - they would know the latest state.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jul 2026 13:30:05 GMT</pubDate>
    <dc:creator>Or</dc:creator>
    <dc:date>2026-07-16T13:30:05Z</dc:date>
    <item>
      <title>Qlik reporting service and vizlib</title>
      <link>https://community.qlik.com/t5/Data-Movement-Streaming/Qlik-reporting-service-and-vizlib/m-p/2551999#M3682</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am starting the assessment of migrating our on-premise Qlik Sense environment to the cloud. We are using Vizlib (Library, Finance) and NPrinting. I would like to know whether Qlik Reporting Service fully supports Vizlib components like NPrinting does, especially for the Vizlib Finance part.&lt;/P&gt;&lt;P&gt;think you&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 14:37:47 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Data-Movement-Streaming/Qlik-reporting-service-and-vizlib/m-p/2551999#M3682</guid>
      <dc:creator>mhoudas78</dc:creator>
      <dc:date>2026-06-24T14:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik reporting service and vizlib</title>
      <link>https://community.qlik.com/t5/Data-Movement-Streaming/Qlik-reporting-service-and-vizlib/m-p/2552098#M3684</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/49569"&gt;@mhoudas78&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Thanks for the questions.&amp;nbsp;&lt;BR /&gt;Third party extensions are currently not supported, as you can see &lt;A href="https://help.qlik.com/en-US/cloud-services/Subsystems/Hub/Content/Sense_Hub/Reporting/Reporting-service-specifications-limitations.htm" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;BR /&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Qlik-Cloud-Analytics-Third-party-extensions-cannot-be-exported/ta-p/1755264" target="_blank" rel="noopener"&gt;This article&lt;/A&gt; explains why we have this limitation.&lt;BR /&gt;On the other side, Qlik Cloud provides many new native objects. I would recommend to use then in combination with the reporting functionality.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2026 15:08:07 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Data-Movement-Streaming/Qlik-reporting-service-and-vizlib/m-p/2552098#M3684</guid>
      <dc:creator>Andrea_Bertazzo</dc:creator>
      <dc:date>2026-06-25T15:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik reporting service and vizlib</title>
      <link>https://community.qlik.com/t5/Data-Movement-Streaming/Qlik-reporting-service-and-vizlib/m-p/2553357#M3688</link>
      <description>&lt;P&gt;The article is more of a marketing statement than a technical one. There is no reason why Qlik could not establish partnerships with professional extension vendors. These vendors are valuable partners who make it possible to use Qlik in specialized business scenarios. Security could be handled in a different way, for example by introducing a Qlik certification process for third-party components.We rely heavily on Vizlib Finance, as there is currently no equivalent solution available in Qlik Cloud. This makes support for Vizlib components a key consideration in our migration assessment.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2026 13:20:32 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Data-Movement-Streaming/Qlik-reporting-service-and-vizlib/m-p/2553357#M3688</guid>
      <dc:creator>mhoudas78</dc:creator>
      <dc:date>2026-07-16T13:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik reporting service and vizlib</title>
      <link>https://community.qlik.com/t5/Data-Movement-Streaming/Qlik-reporting-service-and-vizlib/m-p/2553360#M3689</link>
      <description>&lt;P&gt;If memory serves, some Vizlib Library objects work in NPrinting (Table works, iirc, and I think Pivot Table does too). I would strongly suggest taking this up with Vizlib Support directly, though - they would know the latest state.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2026 13:30:05 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Data-Movement-Streaming/Qlik-reporting-service-and-vizlib/m-p/2553360#M3689</guid>
      <dc:creator>Or</dc:creator>
      <dc:date>2026-07-16T13:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik reporting service and vizlib</title>
      <link>https://community.qlik.com/t5/Data-Movement-Streaming/Qlik-reporting-service-and-vizlib/m-p/2553363#M3692</link>
      <description>&lt;P&gt;We use&amp;nbsp; nprinting and vizlib&amp;nbsp; there is no problem for us bus we study migration&amp;nbsp; to the cloud&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2026 13:42:48 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Data-Movement-Streaming/Qlik-reporting-service-and-vizlib/m-p/2553363#M3692</guid>
      <dc:creator>mhoudas78</dc:creator>
      <dc:date>2026-07-16T13:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik reporting service and vizlib</title>
      <link>https://community.qlik.com/t5/Data-Movement-Streaming/Qlik-reporting-service-and-vizlib/m-p/2553365#M3693</link>
      <description>&lt;P&gt;I fully understand the architectural rationale behind this decision. Running arbitrary third-party JavaScript inside a cloud reporting microservice would indeed introduce significant security and operational risks.&lt;/P&gt;&lt;P&gt;However, there are several technical approaches that could mitigate these risks without completely excluding trusted third-party extensions.&lt;/P&gt;&lt;P&gt;1. Vendor certification program&lt;/P&gt;&lt;P&gt;Qlik could establish a certification process for extension vendors.&lt;/P&gt;&lt;P&gt;Certified extensions would undergo:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Source code review&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Dependency analysis&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Vulnerability scanning&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Penetration testing&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Performance and memory validation&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Compatibility testing with the Qlik Reporting Service&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Only certified versions would be allowed to execute within the reporting infrastructure.&lt;/P&gt;&lt;P&gt;This model is already common in many enterprise software ecosystems.&lt;/P&gt;&lt;P&gt;2. Trusted extension whitelist&lt;/P&gt;&lt;P&gt;Instead of blocking all third-party extensions, Qlik could maintain a whitelist of approved extensions.&lt;/P&gt;&lt;P&gt;During report generation, the Reporting Service could verify:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Extension identifier&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Version&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Digital signature&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Certification status&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If all checks succeed, the extension would be executed. Otherwise, the request would be rejected.&lt;/P&gt;&lt;P&gt;This approach significantly reduces the attack surface while supporting trusted partners.&lt;/P&gt;&lt;P&gt;3. Digital code signing&lt;/P&gt;&lt;P&gt;Each certified extension package could be digitally signed by its publisher.&lt;/P&gt;&lt;P&gt;Before execution, the Reporting Service would verify:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Publisher authenticity&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Package integrity&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Signature validity&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Unsigned or modified extensions would never be executed.&lt;/P&gt;&lt;P&gt;This mechanism is widely used for browser extensions, operating systems and enterprise software deployment.&lt;/P&gt;&lt;P&gt;4. Sandboxed execution&lt;/P&gt;&lt;P&gt;Instead of running extensions directly inside the reporting engine, they could execute in an isolated sandbox.&lt;/P&gt;&lt;P&gt;Possible technologies include:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Dedicated containers&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Restricted JavaScript runtimes&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Browser sandboxing&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Read-only execution environments&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;WebAssembly where applicable&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The execution environment would have:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;No file system access&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;No network access&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;No operating system access&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Strict CPU and memory limits&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Execution time limits&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Even if an extension contained malicious code, its impact would remain isolated.&lt;/P&gt;&lt;P&gt;5. Restricted Reporting SDK&lt;/P&gt;&lt;P&gt;Extensions used only for report rendering do not require full access to the Qlik platform.&lt;/P&gt;&lt;P&gt;Qlik could expose a dedicated Reporting SDK limited to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Data retrieval&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Layout information&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Rendering APIs&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Sensitive platform capabilities would remain unavailable.&lt;/P&gt;&lt;P&gt;This follows the principle of least privilege.&lt;/P&gt;&lt;P&gt;6. Runtime policy enforcement&lt;/P&gt;&lt;P&gt;The Reporting Service could enforce runtime policies such as:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Maximum execution time&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Maximum memory consumption&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Allowed API calls&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Maximum output size&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Blocked browser APIs&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;No external network requests&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Extensions violating these rules would be automatically terminated.&lt;/P&gt;&lt;P&gt;7. Shared responsibility with certified partners&lt;/P&gt;&lt;P&gt;Partners such as Vizlib could assume responsibility for maintaining compatibility with each Qlik Cloud release.&lt;/P&gt;&lt;P&gt;Qlik would certify the platform integration, while partners would certify functional compatibility of their extensions.&lt;/P&gt;&lt;P&gt;This shared responsibility model is already common in enterprise cloud platforms.&lt;/P&gt;&lt;P&gt;8. Customer-controlled trust model&lt;/P&gt;&lt;P&gt;Enterprise customers could explicitly decide whether to allow certified extensions within their tenant.&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Native Qlik visualizations only (default)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Qlik-certified partner extensions&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Organization-approved certified extensions&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This gives each customer the flexibility to choose the level of security and governance that best matches their internal policies.&lt;/P&gt;&lt;P&gt;Why this matters&lt;/P&gt;&lt;P&gt;Companies like Vizlib are not unknown third-party developers. They are long-standing Qlik technology partners whose products have become an integral part of many enterprise deployments.&lt;/P&gt;&lt;P&gt;In our case, we rely heavily on Vizlib Finance because there is currently no native Qlik Cloud equivalent offering the same financial reporting capabilities. Rebuilding these reports using native visualizations would require a significant investment while still resulting in reduced functionality.&lt;/P&gt;&lt;P&gt;The current limitation therefore represents a significant obstacle for organizations evaluating a migration from Qlik Sense Enterprise on Windows to Qlik Cloud.&lt;/P&gt;&lt;P&gt;A trusted extension framework based on certification, digital signatures, sandboxing and runtime controls could provide a balanced solution that protects the platform while preserving the advanced functionality that many enterprise customers depend on.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2026 13:55:50 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Data-Movement-Streaming/Qlik-reporting-service-and-vizlib/m-p/2553365#M3693</guid>
      <dc:creator>mhoudas78</dc:creator>
      <dc:date>2026-07-16T13:55:50Z</dc:date>
    </item>
  </channel>
</rss>

