IHE / IT-Infrastructure

Online repository for information assets supporting the profiles (implementation specifications) in the IHE IT Infrastructure Technical Framework.
Creative Commons Attribution 4.0 International
33 stars 13 forks source link

Problematic statement on Authentication and Authorization #68

Closed msmock closed 4 years ago

msmock commented 4 years ago

Section 34.6, Line 461 in IUA.b, Rev.1.2 from September 21, 2019: The XUA profile provides equivalent functionality for SOAP based transactions. In addition, the SAML token option in IUA enables an Identity Provider (Authorization Server) to exchange an XUA compatible SAML token for an OpenID Connect compatible token which can subsequently be used as an access token in all RESTful transactions specified in MHD, PDQm and other FHIR-based IHE profiles. The exchange of an XUA token for a JWT can take place without additional authorization, so it can be easily implemented by protocol translation gateways.

The statement is problematic in certain aspects:

msmock commented 4 years ago

refactored the working version separate the terms.