Uploaded image for project: 'FHIR Specification Feedback'
  1. FHIR Specification Feedback
  2. FHIR-35350

Change permission-offline to required

    XMLWordPrintableJSON

Details

    • Icon: Change Request Change Request
    • Resolution: Persuasive with Modification
    • Icon: Medium Medium
    • International Patient Access (FHIR)
    • 0.1.0
    • Patient Care
    • STU
    • Security and Privacy
    • Hide

      We'll mandate some capabilities, recommend others, as follows:

      Servers SHALL support client-public, and client-asymmetric.

      Functionally, apps are required to support a number of these capabilities in order to function. IPA will explain to apps the importance of supporting SMART in order to maximize their interoperability.

      Show
      We'll mandate some capabilities, recommend others, as follows: Servers SHALL support client-public, and client-asymmetric. Functionally, apps are required to support a number of these capabilities in order to function. IPA will explain to apps the importance of supporting SMART in order to maximize their interoperability. SHALL launch-standalone context-standalone-patient permission-patient permission-offline sso-openid-connect client-public client-confidential-asymmetric SHOULD and other capabilities defined in SMART MAY be supposed, such as: launch-ehr context-ehr-patient permission-user client-confidential-symmetric
    • Emma Jones / Isaac Vetter: 6-0-0
    • Enhancement
    • Compatible, substantive
    • Yes

    Description

      http://hl7.org/fhir/uv/ipa/2022Jan/security.html – we should require support for permission-offline; if a server does not support this capability, many classes of patient-facing apps become unusable. National standards like US EHR Certification today already require servers to support refresh tokens, so codifying this requirement in IPA would simply documenting an already-widely-adopted profiling decision.

      Attachments

        Activity

          People

            Unassigned Unassigned
            jmandel Josh Mandel
            Josh Mandel
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: