# Regence AI FLEXCUBE POC connector

Read-only API facade with a working synthetic adapter and a configurable HTTPS REST adapter. Native Oracle operations must be mapped and validated with the evaluating bank. SOAP, live credit inference, production SSO, core writes and automated approvals are not implemented in this package.

## Run locally
Python 3.12+; no external Python dependencies.

```sh
export FLEXCUBE_MODE=mock
export POC_TOKENS_JSON='{"REPLACE_WITH_RANDOM_TOKEN_OF_AT_LEAST_32_CHARS":{"clientId":"bank-evaluation","customers":["DEMO-C001"],"loans":["DEMO-L001"],"branches":["001"],"entities":["DEMO"]}}'
python app.py
```

Use `python -c 'import secrets; print(secrets.token_urlsafe(32))'` to generate a local token. Store deployment secrets outside source control. Public documentation is at `/integrations/flexcube/`; API prefix at the hosted demo is `/integration-api`.

```sh
curl http://127.0.0.1:8091/v1/customers/DEMO-C001/loans \
  -H "Authorization: Bearer $POC_TOKEN" \
  -H 'X-Bank-Branch: 001' -H 'X-Bank-Entity: DEMO'
```

The server requires `POC_TOKENS_JSON` with explicit allowed customer, loan, branch and entity identifiers. Missing context returns 400; invalid authentication 401; scope failure 403. Limit: 60 authenticated inquiries/minute/client. Each result has request ID, mode, synthetic flag, retrieval timestamp, source and completeness. Monetary values are decimal strings. No CORS access is enabled; call from a bank backend or integration client, not an untrusted public browser.

## Bank REST sandbox configuration

1. Obtain exact release/patchset, deployed operation paths, schemas and bank-approved authentication. The example profile is deliberately a placeholder, not an Oracle catalog.
2. Copy `profile.example.json` outside source control. Map the five operation keys `customer`, `accounts`, `loans`, `schedule`, `security` as enabled. Paths can use `{id}`, `{branch}`, `{entity}`. Only GET is permitted. Configure response `dataPointer`, `many` and per-field JSON pointers, plus mandatory ownership pointers for branch, entity, customer and requested record. Unmapped operations return 501.
3. Set `FLEXCUBE_MODE=rest`, `FLEXCUBE_PROFILE=/secure/profile.json`, `FLEXCUBE_ALLOWED_HOSTS=sandbox.bank.example` and referenced credential environment variables. Use `FLEXCUBE_CA_FILE` for private bank CA, and `FLEXCUBE_CLIENT_CERT` / `FLEXCUBE_CLIENT_KEY` for mTLS where supported. Verification remains enabled; redirects are rejected. Credentials never enter the model or browser.
4. Configure bank authorization/source registration and service identity. Configure the bank gateway's OAuth token or other required headers through `headerEnv`; automatic OAuth token renewal is not provided. The example encrypted-password headers require the bank's approved encryption process. Do not use raw login passwords as encrypted values.
5. Grant only pilot records to the connector token. Establish private network routing; place behind the bank's production-grade API gateway for concurrency limits, request deadlines, SSO, audit retention and monitoring. Public demo access is only for synthetic data.
6. Validate against bank reference records and exercise missing fields, ownership mismatches, expired credentials, outages and end-of-day behavior before expanding scope.

Response shapes are in `openapi.json`. All sources are partial by default. The `/credit-context` endpoint is a customer profile, not an aggregate exposure calculation. A loan schedule fixture contains a single illustrative installment, not a complete contractual schedule. A successful health response verifies the adapter process, not the bank backend. No POST endpoints are implemented, including the strategy's proposed review-creation endpoint.

No automatic retries or persistent cache are used. Upstream timeout is 10 seconds; response size capped at 2 MB. Failures do not become zero balances. Logs contain only request IDs, operation and status; production audit storage and reviewer/model lineage belong in the surrounding Regence service.

## Verification

```sh
python -m unittest discover -s tests -v
```

Mock HTTP contract/auth/scope/write-denial tests and REST transport/schema/error tests are provided. A live bank sandbox has not been tested. Never describe the mock connector as certified by Oracle or integrated with a particular bank.

## Docker

```sh
docker build -t regence-flexcube-poc .
docker run --read-only --cap-drop ALL --security-opt no-new-privileges \
  -p 127.0.0.1:8091:8091 --env-file /secure/flexcube.env regence-flexcube-poc
```

Public HTTPS proxy strips `/integration-api` before forwarding. Keep upstream port private. This service is for a bounded POC, not a production core banking gateway.
