Secured External Resources
General
Smart Document allow you to pull external resources (images, pdf files or others) from a secured repository to work with our Image, Merge Document and Attach Files functions. These functions are respectively inserting an image, merging a PDF document into a generated PDF, attaching a file into a generated Word document.
As a reminder for those three functions, the quote cell(s) or field(s) used to pull external resource must be of type URL.
URL API are not supposed to be displayed in the UI and should only be used for document generation. If you would need your user to access the document from the Quote UI another URL column should be set up with a Viewer link / Public URL.
OAuth 2.0 Authentication
To access those secured external resource when generating a document, an authentication mechanism must be setup in the PROS Cloud as well as some access right on the external file repository.
SharePoint resources
CERTIFICATE-BASED AUTHENTICATION (JWT BEARER TOKEN AUTHENTICATION)
The Microsoft recommended way for authentication with SharePoint is OAuth 2.0 Client Credentials Flow with Certificate-based Authentication. Microsoft calls this "Certificate credentials" or "Client assertion with certificate" in their documentation. It's also known as JWT Bearer Token Authentication.
Azure AD Setup & Configuration
Step 1: Create Azure AD App Registration
In Azure Portal > Azure Active Directory (Entra Id) > App registrations
- Click "New registration".
- Name: "SharePoint Certificate Auth App".
- Supported account types: "Single tenant".
- Redirect URI: Leave empty (not needed for client credentials).
- Click "Register".
Step 2: Note Application Details
Save these values from the Overview page:
- Application (client) ID: df15de9b-49ea-4d22-b974-68c08a312cbf
- Directory (tenant) ID: e3c40aa4-4fc8-4430-80e0-ff02ed844ecb
- Tenant Name: YourTenantName Image Added
Step 3: Upload Certificate
In App Registration > Certificates & secrets > Certificates
- Click "Upload certificate".
- Select your .cer or .pem certificate file (public key only).
- Add description: For example "SharePoint Authentication Certificate".
- Click "Add".
- Note the Thumbprint: [matches SHA-1 from your certificate].
Step 4: Configure API Permissions
In App Registration > API permissions
- Click "Add a permission".
- Select "SharePoint". This is mandatory, we currently only support SharePoint REST API V1.
- Choose "Application permissions".
- Select required permissions:
- Sites.Read.All (or Sites.FullControl.All)
- Files.Read.All (or Files.ReadWrite.All)
- Click "Grant admin consent for [tenant]".
Authentication
The authentication for SharePoint is richer than the standard OAuth 2.0 authentication. You will need to provide the support team with the following information via a Support Ticket:
| Item | Syntax |
| endpoint | https://MyCompany.sharepoint.com/ |
| clientId | UUID |
| tenantId | UUID |
| tenantName | YourTenantName |
| keyStoreName | sharepointauthkeystore.pfx |
| keyStorePass The same pass MUST be used for keystore and private key. | VAULT::abc-keystorepass |
| keyStoreType | PKCS12 |
| acceptSelfSigned | false |
| accessTokenUrl (Must be provided if different from the default value) | https://login.microsoftonline.com/{tenantId}/oauth2/v2.0/token |
| scopes (Must be provided if different from the default value, multiple values supported) | https://{tenantName}.sharepoint.com/.default |
| audience (Must be provided if different from the default value) | same as accessToken url by default |
AUTHENTICATION WITH CLIENT CREDENTIALS (AZURE COMMUNICATION SERVICES: ACS)
This method of authentication will be deprecated by Microsoft in April 2026 as announced by Microsoft.
Extract of Microsoft Announcement below:
"Azure ACS will stop working for new tenants as of November 1st, 2024 and it will stop working for existing tenants and will be fully retired as of April 2nd, 2026. "
Full announcement available here: https://learn.microsoft.com/en-gb/sharepoint/dev/sp-add-ins/retirement-announcement-for-azure-acs
Prerequisite: SharePoint setup
Some SharePoint Setup is necessary before being able to work with Smart Document. Some of these actions will be taken by your SharePoint administrator.
Activate App-Only via Powershell
- Open SharePoint Online Management Shell
- Open PowerShell
- Execute the following commands in PowerShell to connect to your sharepoint site and activate sharepoint app-only
- Install -Module -Name Microsoft.Online.PowerShell
- $adminUPN="<the full email address of a SharePoint administrator account, example: [email protected]>"
- $orgName="<name of your Office 365 organization, example: contosotoycompany>"
- $userCredential = Get-Credential -UserName $adminUPN -Message "Type the password."
- Connect-SPOService -Url https://$orgName-admin.sharepoint.com -Credential $userCredential
- set-spotenant -DisableCustomAppAuthentication $false
Enable & Configure App-Only
Step 1: Set up an app-only principal with tenant permissions
https://docs.microsoft.com/en-us/sharepoint/dev/solution-guidance/security-apponly-azureacs
| Navigate to a site in your tenant https://MyCompany.sharepoint.com/ Call the appregnew.aspx page https://MyCompany.sharepoint.com/_layouts/15/appregnew.aspx Click on the Generate button to generate a client id/app id and client secret and fill the remaining info For example Title: DocGenPROS AppDomain: www.MyCompany.com Redirect URL: http://www.MyCompany.com/default.aspx |
Step 2: Grant permissions to the newly created principal
Possible scopes for the permission request:
Below are the various App permission level that are available in SharePoint
| SCOPE | SCOPE URI | DESCRIPTION |
|---|---|---|
| Tenancy | http://sharepoint/content/tenant | The tenancy where the permission is granted. Includes all children of this scope. |
| Site Collection | http://sharepoint/content/sitecollection | The site collection where the permission is granted. Includes all children of this scope. |
| Website | http://sharepoint/content/sitecollection/web | The website where the permission is granted. Includes all children of this scope. |
| List | http://sharepoint/content/sitecollection/web/list | A single list in the website where the permission is granted. |
Step 3: Retrieve the TenantID and ClientID
As you will need to give this information to Conga, this is how you can retrieve your TenantID and ClientID.
Use a Postman GET Method
| URL | HEADER | OUTPUT | |
|---|---|---|---|
| GET the Tenant ID | https://MyCompany.sharepoint.com/_vti_bin/client.svc/ | Authorization: Bearer | realm (corresponds to the TenantID) clientID |
AUTHENTICATION
The authentication for SharePoint is richer than the standard OAuth 2.0 authentication. You will
need to provide the following information via a Support Ticket:
| Item | Syntax |
| endpoint | https://MyCompany.sharepoint.com/ |
| accessTokenUrl | https://accounts.accesscontrol.windows.net/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxx/tokens/OAuth/2 https://accounts.accesscontrol.windows.net/TenantID/tokens/OAuth/2 |
| clientId | xxxxxxxx-xxxx-xxx-xxx-xxxxxxxx@xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxx AppID@TenantID |
| clientSecret | xxxxxxxxxxxxx |
| resource | xxxxxxxx-xxxx-xxx-xxx-xxxxxxxx/MyCompany.sharepoint.com@xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxx ClientID/MyCompany.sharepoint.com@TenantID |
COMPLIANT URL FORMAT
URL used in the Document Generation are stored in the CPQ Quote. Performance Quoting has trict URL validation process. You cannot use URLs with '(' or ')'.
SharePoint Rest API URL may contain some of those forbidden characters. '(' or ')' must be encoded as follow when used in the quote.
| https://xxx.sharepoint.com/sites/urlSecurityDemo/_api/web/GetFolderByServerRelativeUrl('Shared%20Documents')/Files('demo.jpeg')/$value | will not work |
| https://xxx.sharepoint.com/sites/urlSecurityDemo/_api/web/GetFolderByServerRelativeUrl%28'Shared%20Documents'%29/Files%28'demo.jpeg'%29/$value | should be used instead |
USEFUL LINKS
Get started with SharePoint Online Management Shell
Granting access using SharePoint App-Only
Types of add-in permissions and permission scopes
Differences between add-in permission rights and user rights
Only Salesforce organizations where the Smart CPQ managed package has been installed can be the repository for the files used as external resources.
Prerequisite: Salesforce setup
STORAGE
Only documents and images stored in the Files entities in Salesforce can be used as external resources during the document generation process. Documents and images stored in the Salesforce Notes & Attachments entities are not eligible for merge, attach and insertion in document generation.
PERMISSIONS
The user launching the document generation must have access to the Salesforce-stored resources. If not, the document generation process will not be able to merge, attach or insert the file.
To learn more about Salesforce Permission read: Who Can See My File?
Authentication
There is no additional setup to perform for authentication as the managed package will take care of it.
Nevertheless, on PROS Cloud side we need to enable the capability, you will need to reach out to create a Support ticket for the team to enable the feature.
Compliant URL Format
URL used in the Document Generation are stored in the CPQ Quote. Performance Quoting has a strict URL validation process. You cannot use URLs with '(' or ')'.
This is how the URL should be built and stored in the Quote:
| Structure Example | {{SALESFORCE_INSTANCE_URL}}/services/data/v{{SALESFORCE_REST_API_VERSION}}/connect/files/{{FILE_ID}}/content |
| Structure Example | https://my.salesforce.com/services/data/v43.0/connect/files/0698W00000SpXHiQAN/content |
WHAT IS THE SALESFORCE INSTANCE URL? (SALESFORCE_INSTANCE_URL)
The Salesforce instance URL must be the domain URL. How to find it?
- Log in to your Salesforce org as an Admin
- Navigate to ‘My Domain’ in Setup
- Look for Current My Domain URL
| Correct URL Incorrect URL | https://pm-qtx.my.salesforce.com |
| Correct URL Incorrect URL | https://pm-qtx.lightning.force.com/ |
HOW TO FIND MY SALESFORCE REST API VERSION NUMBER? (SALESFORCE_REST_API_VERSION)
- Log in to your Salesforce org as an Admin
- Navigate to ‘Apex Classes’ in Setup
- Click on the ‘New’ button
- Click ‘Version Settings’ tab
There you can see which API version your Salesforce instance is on.
WHERE TO FIND THE IDENTIFIER OF THE FILE ? (FILE_ID)
The file ID can be found in the URL when opening the "View file details" page.
