Setting Up OCI Process Automation Integration
This topic describes how to set up the integration between Oracle Permitting and Licensing and Oracle Cloud Infrastructure Process Automation.
Before you begin your Oracle Permitting and Licensing implementation, you need to configure the connection between OCI Process Automation and Oracle Permitting and Licensing. OCI Process Automation provides the capability to design and process:
- 
                Workflow for your transactions. 
- 
                Decision models for calculating fees. 
These steps should be done within the Initial Set Up functional category for your offering in the Functional Setup Manager. The process involves setting up the users, groups (roles), and authentication in Oracle Identification Cloud Service (IDCS) required for OCI Process Automation and the Permitting and Licensing system to interact.
You need to complete these tasks on each pod (test, development, production, and so on) for each pairing of Oracle Identity Cloud Service and Oracle Cloud Infrastructure Process Automation.
Create a Trusted User on IDCS
This step is required only if you haven't migrated from Identity and Access Management (IAM) to Oracle Cloud Infrastructure Identity and Access Management (OCI IAM). Also note the product name change from Oracle Cloud Identity Service (IDCS) to Oracle Cloud Infrastructure Identity and Access Management (OCI IAM).
As part of Oracle's efforts to enhance the technology and capabilities for Fusion Applications, Identity and Access Management (IAM) for your Fusion environment(s) will be upgraded to Oracle Cloud Infrastructure Identity and Access Management (OCI IAM) in the coming months.
- 
                    Sign in to the Identity Cloud Service console. Note:On the sign in dialog, don't sign into the Default identity domain. Sign into the specific domain for which you will be running the configuration steps. 
- 
                    Select Identity > Domains and select your domain. 
- 
                    Select Users. 
- 
                    Click Create User. 
- On the Create user page, add these values:- 
                            First name: PSCR 
- 
                            Last name: PROXY_USER 
- 
                            Use the email address as the username: Deselect 
- 
                            Username: PSCR_PROXY_USER Note:If you copy this value from the guide, paste it into a text editor first to confirm you haven't picked up any random markup characters from the HTML. 
- 
                            Email: no-reply@oracle.com 
 Note:The First Name, Last Name, and Email values can be any value. The Username value must be PSCR_PROXY_USER. 
- 
                            
- Click Create.
Create the PSCR Submitter Group
This step is required only if you haven't migrated from Identity and Access Management (IAM) to Oracle Cloud Infrastructure Identity and Access Management (OCI IAM). Also note the product name change from Oracle Cloud Identity Service (IDCS) to Oracle Cloud Infrastructure Identity and Access Management (OCI IAM).
As part of Oracle's efforts to enhance the technology and capabilities for Fusion Applications, Identity and Access Management (IAM) for your Fusion environment(s) will be upgraded to Oracle Cloud Infrastructure Identity and Access Management (OCI IAM) in the coming months.
- 
                    Sign in to the Identity Cloud Service console. Note:On the sign in dialog, don't sign into the Default identity domain. Sign into the specific domain for which you will be running the configuration steps. 
- 
                    Select Identity > Domains and select your domain. 
- 
                    Select Groups. 
- 
                    Click Create Group. 
- 
                    On the Create group page, add these values: - 
                            Name: PSCR Submitter Group 
- 
                            Users grid: select the trusted user you just created. 
 
- 
                            
- 
                    Click Create. 
Set Up Cloud Service Application Roles
- 
                    In Functional Setup Manager, complete the Run User and Roles Synchronization Process task in the Initial Setup Functional area. 
- 
                    In IDCS import users into the identity domain. 
- 
                    Sign in to the Identity Cloud Service console. Note:On the sign in dialog, don't sign into the Default identity domain. Sign into the specific domain for which you will be running the configuration steps. 
- 
                    Select Identity > Domains and select your domain. 
- 
                    Select Oracle Cloud Services. 
- 
                    Open the IDCS app named Process Automation Service. 
- 
                    Select Application roles under Resources on the left. 
- 
                    Expand the ServiceAdministrator role and click Manage for Assigned groups. 
- 
                    On the Manage group assignments page, click the plus sign in the Show available groups link beneath the Assigned groups grid to expose the Available groups grid. 
- 
                    In the Available groups grid, search for and select the following groups individually, and click Assign. - 
                            PSCR Submitter Group 
- 
                            PSC System Administrator 
- 
                            PSC Business Analyst 
- 
                            PSC Custom Manage All Workflow Tasks 
- 
                            PSC Custom Administer Workflow 
 
- 
                            
- 
                    Click Close. 
- 
                    In the Application roles list, expand the ServiceBusinessUser role and click Manage for Assigned groups. 
- 
                    On the Manage group assignments page, search for and select the PSC Agency Staff group and click Assign. 
Confirm OCI Process Automation Authentication
- 
                    Access the OCI Process Automation designer URL. It will look similar to: https://opa-xxx-xxx-xxxxxxx.process.oci.oraclecloud.com/process/designer It is recommended to create a bookmark for easy access. You can get the base URL by accessing the Primary Audience URL, as displayed in the IDCS App for the Process Automation Service. Assuming you are still on the Manage group assignments page from the previous step, you can also access this URL by clicking OAuth configuration under Resources on the left. In the Configure application APIs that need to be OAuth protected, locate the Primary audience URL. Note:Keep the Primary audience URL available as you'll need it in the next task.. 
- 
                    Enter your user ID and password and confirm you can sign in. Use a Fusion Application user ID assigned at least to the PSC System Administrator role. 
Create OAuth Credentials
- 
                    Sign in directly to the individual identity domain. By viewing the My Profile menu, you can see if you are signed into a specific domain or through the (default) domain. If you are logged into the default domain, you an get the URL for an individual identity domain, by selecting Identity > Domains. In the domains grid select the domain you are currently configuring. On the Over view page for that domain click Copy for the Domain URL field. Open a new browser window and copy that URL into the search bar, adding /ui/vi/adminconsole to the URL. 
- 
                    Open your REST client application, such as Postman, Curl, or similar. 
- 
                    Add the Domain URL value to the Identity Cloud Service console and select the POST action. Add /admin/v1/Apps to your base Domain URL. The URL will look similar to: https://idcs-abc123xxxxxxxxxx.identity.oraclecloud.com/admin/v1/Apps 
- 
                    In the body, copy and paste the following JSON, updating the name and the redirectUris attributes. The user assigned to name should be created in Permitting and Licensing with sufficient privileges to call Oracle Permitting and Licensing from OCI Process Automation through REST APIs. This isn't the user created previously in the step where you created a trusted user on IDCS. This user will be added to your workflow process connectors. This isn't a typical functional user, but a user with elevated access, such as a system administrator. The redirectUris URL should use the URL displayed as the Primary audience URL for your domain to which you add /icsapis/agent/oauth/callback. { "schemas": [ "urn:ietf:params:scim:schemas:oracle:idcs:App" ], "displayName": "OPA App for PSCR OAuth Inbound", "isOAuthClient" : true, "description": "OPA App for PSCR OAuth Inbound", "active": true, "clientType": "confidential", "name": "xxxxx", "basedOnTemplate": { "value": "CustomWebAppTemplateId" }, "redirectUris": [ "<OCI Process Automation Base URL>/icsapis/agent/oauth/callback" ], "logoutUri": "", "postLogoutRedirectUris": [""], "allUrlSchemesAllowed": true, "allowedGrants": [ "client_credentials", "password", "urn:ietf:params:oauth:grant-type:jwt-bearer", "authorization_code", "refresh_token" ] }
- 
                    Retrieve and copy your OAuth token. - 
                            In Oracle Identity Service console, select the Profile menu in the upper right of the header. 
- 
                            Select My profile. 
- 
                            Under Resources, click My access tokens. 
- 
                            Under My access tokens, click the Select app role field. 
- 
                            Select Identity Domain Administrator. 
- 
                            Consider the Token expires in mins field. You may want to set this to a higher value than the default to provide additional time. Keep in mind that if you need to retry this operation for any reason, your token may have expired, so you'd need to recreate the token. 
- 
                            Click Download token. 
- 
                            Open the downloaded token in a text editor, such as Notepad. 
- 
                            Copy the contents of the token file. 
 
- 
                            
- 
                    Return to your REST client, click the Authorization tab, select Bearer Token for the Type field, and copy the token file contents into the Token field. 
- 
                    Click Send. 
- 
                    Return to the Oracle Identity Service console and open your domain. In the navigation breadcrumbs at the top left, click Identity, then click Domains under Identity on the left, click on your domain in the Domains in... grid. 
- 
                    Under Identity domain, select Integrated applications. 
- 
                    On the Integrated applications page, select OPA App for PSCR OAuth Inbound. 
- 
                    Under OAuth configuration, click Edit OAuth configuration. 
- 
                    On the Edit OAuth configuration page: - 
                            Select Add resources. 
- 
                            Under Resources click Add scope. 
- 
                            On the Add scope page, select Oracle Applications Cloud (Fusion). 
- 
                            Expand the Oracle Applications Cloud (Fusion) row, and select the scope that appears. Note:The string reflects that your Fusion Application instance is a consumer of all Fusion Application resources. 
- 
                            Click Add and Save changes. 
 
- 
                            
Set OAuth Credentials in OCI Process Automation
- 
                Return to OCI Process Automation designer. For example: https://opa-xxx-xxx-xxxxxxx.process.oci.oraclecloud.com/process/designer 
- 
                Select the Workspace node in the left navigation column. 
- 
                In the Workspace, select Credentials. 
- 
                In the upper right click Create global credentials, and select OAuth credentials. 
- 
                On the Add new OAuth credential page, add these values: - 
                        Credential Name: OPAL_OPA_GLOBAL_OAUTH 
- 
                        Target URL: Add the Fusion Application base URL for the current pod, such as https//fa-xxxx-xx-xx.fa.xx.oraclecloud.com. This is the base URL when signing on to Oracle Permitting and Licensing. 
- 
                        Client Id: Add the name you added to the JSON in a previous step when creating the OAuth credentials. 
- 
                        Client Secret: Return to your OAuth configuration in the Oracle Identity Service console for the current domain, and under General Information, click Show secret. From the Client secret pop-up window, copy the secret, and paste it into the Client Secret field. 
- 
                        Scope: Return to your OAuth configuration in the Oracle Identity Service console for the current domain, and under Token issuance policy, select and copy the Scope value for the Oracle Applications Cloud (Fusion) resource. Paste it into the Scope field. 
- 
                        OAuth Token URL: Select Local Identity Domain. 
- 
                        Description: Add a description, such as, Global OAuth credentials for callbacks to <your Permitting and Licensing pod>. 
- 
                        Click Submit. 
 
-