Uploaded image for project: 'FHIR Specification Feedback'
  1. FHIR Specification Feedback
  2. FHIR-32325

Add best practices for app developers

    XMLWordPrintableJSON

Details

    • Icon: Change Request Change Request
    • Resolution: Persuasive
    • Icon: Medium Medium
    • SMART on FHIR (FHIR)
    • 2.0.0
    • FHIR Infrastructure
    • STU
    • Best Practices
    • Hide

      Add the following to the Best Practices Page:


      Best practices for app developers include:

      • Ensure that refresh tokens are never used more than once
      • Take advantage of techniques to bind refresh tokens to asymmetric secrets managed in hardware, when available (see above)
      • If an app only needs to connect to EHR when the user is present, maintain secrets with best-available protection (e.g., biometric unlock)

      Publicly document any code of conduct that an app adheres to (e.g., CARIN Alliance code of conduct)

      Show
      Add the following to the Best Practices Page: — Best practices for app developers include: Ensure that refresh tokens are never used more than once Take advantage of techniques to bind refresh tokens to asymmetric secrets managed in hardware, when available (see above) If an app only needs to connect to EHR when the user is present, maintain secrets with best-available protection (e.g., biometric unlock) Publicly document any code of conduct that an app adheres to (e.g.,  CARIN Alliance code of conduct )
    • Gino Canessa/Yunwei Wang: 13-0-0
    • Enhancement
    • Non-substantive

    Description

      The non-normative best practices page should include the following

      Best practices for app developers include:

      • Ensure that refresh tokens are never used more than once
      • Take advantage of techniques to bind refresh tokens to asymmetric secrets managed in hardware, when available (see above)
      • If an app only needs to connect to EHR when the user is present, maintain secrets with best-available protection (e.g., biometric unlock)

      Publicly document any code of conduct that an app adheres to (e.g., CARIN Alliance code of conduct)

      Attachments

        Activity

          People

            carl-anderson-msft Carl Anderson (Inactive)
            jmandel Josh Mandel
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: