Skip to main content

Suggest an Idea

Vote for your favorite Qlik product ideas and add your own suggestions.

Announcements
This page is no longer in use. To suggest an idea, please visit Browse and Suggest.

Support uploading of mashups to Qlik SaaS

fukicubiq
Partner - Contributor II
Partner - Contributor II

Support uploading of mashups to Qlik SaaS

In client managed Qlik Sense, mashups are uploaded to Qlik server just like any other extension. For some reason, Qlik SaaS allows only uploading of custom object extensions. This creates problems because:

  1. Mashups need to be hosted on a separate web server, increasing management overhead and infrastucture costs. In a corporate environment, it is never straightforward to establish new web servers or get admin access to existing ones.
  2. Because mashups are hosted on a different domain than Qlik SaaS, authentication may not work at all as modern browsers increasingly limit the use of 3rd party cookies. Safari already blocks 3rd party cookies by default, making it impossible to use a Qlik mashup unless the user knows how to override the default security settings. Chrome is likely to do the same starting next year.
  3. Requiring mashups to be hosted on a separate web server decreases overall security as it can open up additional attack vectors and requires more effort to setup and maintain security. Any attack that is possible using mashups can be done with custom object extensions, so allowing mashups to be uploaded in Qlik SaaS does not really open any additional attack vectors. In the end, only administrators can upload extensions to Qlik SaaS and one should assume that they are trustworthy and responsible.

The solution to the above is simple: just please allow uploading of mashups like other extensions in Qlik SaaS!

Tags (3)
3 Comments
Stas_vd_Braber
Partner - Contributor II
Partner - Contributor II

Great suggestion. My client has also issues with the authentication, as Safari already blocks the 3rd party cookies. Qlik uses an iFrame for their download site (https://community.qlik.com/t5/Downloads/tkb-p/Downloads) Therefore I can imagine that finding a way of authentication without the use of 3rd party cookies has high priority for them too.  

Meghann_MacDonald

From now on, please track this idea from the Ideation portal. 

Link to new idea

Meghann

NOTE: Upon clicking this link 2 tabs may open - please feel free to close the one with a login page. If you only see 1 tab with the login page, please try clicking this link first: Authenticate me! then try the link above again. Ensure pop-up blocker is off.

Ideation
Explorer II
Explorer II
 
Status changed to: Closed - Archived