<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Automated login when embedding with OAuth2 in Integration, Extension &amp; APIs</title>
    <link>https://community.qlik.com/t5/Integration-Extension-APIs/Automated-login-when-embedding-with-OAuth2/m-p/2162136#M19722</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;From reading&amp;nbsp;&lt;A href="https://qlik.dev/embed/foundational-knowledge/best-practice-auth/" target="_blank"&gt;Auth best practices for embedding | Qlik Developer Portal&lt;/A&gt;, it is my understanding that the recommended way to achieve silent authentication when embedding Qlik Content into a web-app/SPA is to &lt;SPAN&gt;conform the source and target applications to use the same identity provider.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Now, for whatever reason, say it isn't viable to conform the IdP of the Qlik Tenant to match the one of the web-app. What is the recommended way to perform silent authentication in this scenario?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I've noticed that both the&lt;/SPAN&gt;&amp;nbsp;&lt;A href="https://qlik.dev/authenticate/oauth/#web-oauth2-client-applications" target="_blank" rel="noopener"&gt;web-app and SPA OAuth2 client application examples on qlik.dev&lt;/A&gt;&amp;nbsp;have a step that's a redirect to /login, which I'd like to avoid.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;From what I know, an alternative would be the use of JWTs, but I worry about the 3rd party coookie issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any insights or pointers in the right direction would be greatly appreciated. Thank you for your assistance.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jan 2024 18:59:12 GMT</pubDate>
    <dc:creator>pperdigo</dc:creator>
    <dc:date>2024-01-16T18:59:12Z</dc:date>
    <item>
      <title>Automated login when embedding with OAuth2</title>
      <link>https://community.qlik.com/t5/Integration-Extension-APIs/Automated-login-when-embedding-with-OAuth2/m-p/2162136#M19722</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;From reading&amp;nbsp;&lt;A href="https://qlik.dev/embed/foundational-knowledge/best-practice-auth/" target="_blank"&gt;Auth best practices for embedding | Qlik Developer Portal&lt;/A&gt;, it is my understanding that the recommended way to achieve silent authentication when embedding Qlik Content into a web-app/SPA is to &lt;SPAN&gt;conform the source and target applications to use the same identity provider.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Now, for whatever reason, say it isn't viable to conform the IdP of the Qlik Tenant to match the one of the web-app. What is the recommended way to perform silent authentication in this scenario?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I've noticed that both the&lt;/SPAN&gt;&amp;nbsp;&lt;A href="https://qlik.dev/authenticate/oauth/#web-oauth2-client-applications" target="_blank" rel="noopener"&gt;web-app and SPA OAuth2 client application examples on qlik.dev&lt;/A&gt;&amp;nbsp;have a step that's a redirect to /login, which I'd like to avoid.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;From what I know, an alternative would be the use of JWTs, but I worry about the 3rd party coookie issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any insights or pointers in the right direction would be greatly appreciated. Thank you for your assistance.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 18:59:12 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Integration-Extension-APIs/Automated-login-when-embedding-with-OAuth2/m-p/2162136#M19722</guid>
      <dc:creator>pperdigo</dc:creator>
      <dc:date>2024-01-16T18:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: Automated login when embedding with OAuth2</title>
      <link>https://community.qlik.com/t5/Integration-Extension-APIs/Automated-login-when-embedding-with-OAuth2/m-p/2162908#M19734</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/177413"&gt;@pperdigo&lt;/a&gt;&amp;nbsp;- Please take a look at these links and see if they can assist:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://qlik.dev/embed/iframe/authenticate/third-party-cookie-handling-with-embedded-content/" target="_blank"&gt;https://qlik.dev/embed/iframe/authenticate/third-party-cookie-handling-with-embedded-content/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Need-to-Know-Embedding-Qlik-Analytics-and-the-End-of-Third-Party/ta-p/2158755" target="_blank"&gt;https://community.qlik.com/t5/Official-Support-Articles/Need-to-Know-Embedding-Qlik-Analytics-and-the-End-of-Third-Party/ta-p/2158755&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Our product teams are dedicated to evolving with the behavior and requirements of modern browsers, please stay tuned as they continue to innovate around embedding by following along at&amp;nbsp;&lt;A href="https://qlik.dev/changelog/" target="_blank"&gt;https://qlik.dev/changelog/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 15:03:47 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Integration-Extension-APIs/Automated-login-when-embedding-with-OAuth2/m-p/2162908#M19734</guid>
      <dc:creator>jprdonnelly</dc:creator>
      <dc:date>2024-01-18T15:03:47Z</dc:date>
    </item>
  </channel>
</rss>

