OAuth server doesn't know what "all relevent info" entails. Authorization rules must be enforced regardless. - DTR #58

XMLWordPrintableJSON

    • Type: Change Request
    • Resolution: Persuasive with Modification
    • Priority: Medium
    • US Da Vinci DTR (FHIR)
    • STU3
    • Clinical Decision Support
    • (profiles) [deprecated]
    • Execution of CQL
    • Hide

      Existing Wording: The SMART on FHIR application MUST be provided with a token that allows it to access all relevant information for the patient in question.

      Replace with:

      The SMART app specifies the scopes it wants during launch which SHOULD be sufficient to access all relevant information. The authorization server (sometimes in conjunction with the authorizing user) determines the list of scopes the app is allowed to have.

      Show
      Existing Wording: The SMART on FHIR application MUST be provided with a token that allows it to access all relevant information for the patient in question. Replace with: The SMART app specifies the scopes it wants during launch which SHOULD be sufficient to access all relevant information. The authorization server (sometimes in conjunction with the authorizing user) determines the list of scopes the app is allowed to have.
    • Bob Dieterle / Rachael Foerster: 7-0-1
    • Correction
    • Non-substantive

      Existing Wording: The SMART on FHIR application MUST be provided with a token that allows it to access all relevant information for the patient in question.

      Comment:

      This is not a useful requirement. The SMART app specifies the scopes it wants during launch. The authorization server (sometimes in conjunction with the authorizing user) determines the list of scopes the app is allowed to have. This sentence should be delted.

      Summary:

      OAuth server doesn't know what "all relevent info" entails. Authorization rules must be enforced regardless.

            Assignee:
            Unassigned
            Reporter:
            Michael Clifton
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: