After following the guide for switching to Visma.net ( -base-in-Developers/Guide-Move-from-VNI-to-Visma-Connect-Aut... I have to make a new REST-connector. We are updating a previous solution, and is therefore in need to get a new refreshable token (due to limited 60min).
I have client_secret, client_id and tenant_id. I would guess the url to be: connect.visma.com/connect/token or connect.visma.com/connect/authorize for the new REST-connector depending on POST or GET. I have used client_id, client_secret and tenant_id as query parameters, but no success.
I have tried to follow this guide -Sense-Documents/Handling-Refresh-Tokens-with-the-Qlik-REST-Connec... but I am not able to get any access token.
I have used postman, where I am able to get an access token that works in qlik for the old solution. Can anyone help me get the same result in Qlik Sense?
In order to gain a positive relationship and avoid misinterpretation and vagueness, we would like you to review the following program rules before you report a vulnerability. By participating in this program, you agree to respect our policy.
In connection with your participation in this program you agree to comply with all applicable local and national laws.
You may not participate in this program if you are currently employed or contracted by Visma.
You may not participate in this program if you are a resident or individual located within a country appearing on any U.S. or E.U. sanctions list.
Visma has never given permission/authorization (either implied or explicit) to an individual or group of individuals to extract personal information or content of Visma's customers and publicize this information on the open, public-facing Internet without customer consent, nor has Visma ever given permission for programs or data belonging to Visma to be modified or corrupted in order to extract and publicly disclose data belonging to Visma.
Visma Scanner
Visma Scanner is a mobile app used for sending receipts and invoices to your Visma accounting system.
The iOS version of the app can be found here:
-scanner/id564141518
Please read and follow the steps in the Startup guide to create an account and start hacking: -getting-started.pdf
Visma Online
This is the old interface for the customer's administrators to administrate the company, where we still have some functionality that has not been moved to the new interface. For example invoicing information and everything regarding collaborations with AO. The collaboration part is out of scope as long as the use of student companies.
Please read the Getting Started Instructions in the "myservices.stage.vismaonline.com" asset description.
This is the main UI for Visma AutoInvoice. AutoInvoice is Visma's automated and fully ERP integrated service for sending, receiving and handling invoices. AutoInvoice converts and exchanges electronic invoices, optionally prints invoices that can't be sent electronically, receives and interpret PDF invoices and offers services for scanning and interpretation of paper invoices. AutoInvoice handles both Business to Business (B2B) and Business to Consumer (B2C) invoices.
Note! ai-testing.maventa.com and testing.maventa.com point to the same application but have different branding on the UI. Authentication to the user interface is handled using the Visma Connect service.
Dinero
Dinero is an accounting software for sole traders and micro businesses based out of Denmark. Our only target group is danish companies and therefore the interface is in danish only. The application is a SaaS application hosted in the cloud and consists of a main application and a number of supportive microservices.
Visma Scanner
Visma Scanner is a mobile app used for sending receipts and invoices to your Visma accounting system.
The Andriod version of the app can be found here:
=com.visma.blue&hl=en
Please read and follow the steps in the Startup guide to create an account and start hacking: -getting-started.pdf
Connect
Visma Connect is featurewise a small but critical component in the Visma portfolio. It is a single sign-on solution used by many Visma services. It is also the place where users manage security preferences such as passwords, MFA, 2FA, email and other account settings.
Visma Online
Visma Connect is used as identity provider, but an own identity server is used to provide JWT tokens that are used by MyServices (and others).
Please read the Getting Started instructions document in the "myservices.stage.vismaonline.com" asset description.
Visma Online
This is the API behind "myservices.stage.vismaonline.com".
Please read the Getting Started instructions document in the asset description "myservices.stage.vismaonline.com".
Visma Online
This is an interface where the customer's users can access all their services, and customer's administrators can manage users on the company and manage users' access to services that the company has.
More information about the service and test accounts creation can be found here:
-getting-started.pdf
Visma Developer Portal
Visma Developer Portal is used both internally and externally by developers for registering OAuth 2.0/OpenID Connect applications for Single-Sign-On with Visma (Visma Connect) and/or API integration.
Users need to register an organization as part of the sign-in or to be added (invite) to an existing organization by organization's manager. The user which registers the organization also gets manager role assigned.
With that said, it is time for us to gear up for the holiday season and take some rest from this hectic year, with that, we will suspend this program soon for the remainder of the year and be back next year stronger than ever!
We are happy to announce the launch of our Public Bug Bounty Program on Intigriti, so if you have discovered a security vulnerability, please inform us through this program and we will do our best to quickly fix it.
Additionally to the bellow general out of scopes, please make sure you always check the asset description under each domain and don't submit issues that are out of scope for those specific domains.
No impact means no bounty. We will always take into consideration the business impact and security impact when setting the final severity of the reports.
Monetary rewards will be offered for qualifying reports. The amount will vary depending on the severity. The "Bounties" section provides a general guideline for the amounts, but final rewards may be adjusted for actual business impact. For example an SQLi for a database containing no sensitive information may be rewarded a lower amount compared to an SQLi for a database with sensitive information.
When duplicates occur, we will only accept the first report. A duplicate is a vulnerability that we are already aware of, regardless of how we first became aware of it (it could have also been discovered by us internally).
c80f0f1006