JDBC provisioning rule

Hello everyone,

For JDBC connector we are defining the provisioning policy to create new accounts. I can see in UI we have options to select values for attributes. So still do we need provisioning rule? If yes what code to be written in create operation section.

if ( AccountRequest.Operation.Create.equals( account.getOperation() ) )

{

//please help me with the code here

}

hi jack;

Though you have provisioning policy in the UI, you still need to write the provisioning rule for jdbc , at first you have to create a connector rule through beta collections for JDBC provisioning and add that rule to your source through update source partial api in v3 collections. I hope the below attachment helps you.
IdentityNow JDBC configuration.docx (718 KB)

Hi Tulasi,

Attached document helps a lot. Appreciate your help here. Thanks a lot!

Hi  @Tulasi

I’m getting below error while trying to attach provision rule to the source. Could you please help me?

URL: PATCH {{baseUrl}}/sources/:id

Request Body:

[    {        “op”: “add”,        “path”: “/connectorAttributes/jdbcProvisionRule”,        “value”: “test_123 jdbc”    }]405Method Not Allowed{    “errorName”: “NotSupportedException”,    “errorMessage”: “RESTEASY003065: Cannot consume content type”,    “trackingId”: “ace07fb4ab1943818e39926c7663ee7c”}

Hi jack,

May be in the headers you didn’t check the accept-type and content -type ,just check them and try again. I hope it works

Thanks you  @Tulasi ! That helped.

Hi  @Tulasi  ,

I got one more question here. In the create operation, data is being written only to users table but not the userscapabilities table. Here the account the being created while I raise entitlement request for user in Sailpoint so we need entitlement data to be written in userscapabilities table as well but my below code is failing to do that. We need both user table and usercapabilities table to be updated fir the forst time in create operation.

if (AccountRequest.Operation.Create.equals(account.getOperation())) {
                    // Ideally we should first check to see if the account already exists.
                    // As written, this just assumes it does not.

                    statement = connection.prepareStatement("insert into accounts(EmpID,EmpName,AccountID) values (?,?,?)");
                    statement.setString(1, (String) account.getNativeIdentity());
                    statement.setString(2, getAttributeRequestValue(account, "EmpName"));
                    statement.setString(3, getAttributeRequestValue(account, "AccountID"));
                    statement.executeUpdate();

                    result.setStatus(ProvisioningResult.STATUS_COMMITTED);

                    List<AttributeRequest> mod_attr_requests1 = account.getAttributeRequests();
                    if (mod_attr_requests1 != null) {
                        for (AttributeRequest req1 : mod_attr_requests1) {
                            if (req1.getName().equals("EmpID")) {
								if (ProvisioningPlan.Operation.Add.equals(req.getOperation())) {
									statement1 = connection.prepareStatement("INSERT INTO sailpoint.groups (EmpID, EntName) values (?, ?)");
									statement1.setString(1, (String) account.getNativeIdentity());
									statement1.setString(2, req1.getValue());
									statement1.executeUpdate();
									result.setStatus(ProvisioningResult.STATUS_COMMITTED);
								}
                            }
                        }
                    }

Hi jack,

I too tried it but i have no idea why I  was unable to insert the entitlements , if u resolved the issue let me know. Thanks in advance.

Hi jack,

try this once,it worked for me

if ( AccountRequest.Operation.Create.equals( account.getOperation() ) ) {            // Ideally we should first check to see if the account already exists.            // As written, this just assumes it does not.             statement = connection.prepareStatement( “insert into user(username,email,userid,userpassword) values (?,?,?,?)” ); PreparedStatement prStatement = connection.prepareStatement(“INSERT INTO usercapabilities (userid, capabilityid) values (?, ?)”);            statement.setString ( 3, (String) account.getNativeIdentity() );            statement.setString ( 1, getAttributeRequestValue(account,“username”) );            statement.setString ( 2, getAttributeRequestValue(account,“email”) );            statement.setString ( 4, getAttributeRequestValue(account,“lastname”) );            statement.executeUpdate(); AttributeRequest attr = account.getAttributeRequest(“capability”); if (attr != null) {  if (attrReq.getValue() instanceof String) { prStatement.setString(1, (String) account.getNativeIdentity());                                prStatement.setString(2, attr.getValue()); } else if (attrReq.getValue() instanceof List) { String listOfRoles = Util.listToCsv((List) attr.getValue()); prStatement.setString(1, (String) account.getNativeIdentity());                                prStatement.setString(2, listOfRoles); } }  int j =prStatement.executeUpdate();             result.setStatus( ProvisioningResult.STATUS_COMMITTED );           }

That works! Thanks for helping me to complete JDBC app onboarding  @Tulasi . Moving down to web connector app onboarding.

Do you know the syntax for ‘nofiltering=true’?  We have read-only access to application database table so write to an alternate table that the application then imports.  The problem is that null values are being written if the data already matches that field.  We are using aliases as mentioned by ‘bilal’ in this article but then we can’t turn on attribute sync for those attributes.  There are a lot of articles for IIQ and workflow but not ISC JDBC Provisioning Rules.