nhsconnect / FHIR-NOO-API

FHIR based API for managing National Opt Out preferences
https://nhsconnect.github.io/FHIR-NOO-API/index.html
Apache License 2.0
0 stars 2 forks source link

Inconsistent JWT usage across FHIR implementations #12

Open ben-clarke opened 6 years ago

ben-clarke commented 6 years ago

The suggested "Cross Organisation Audit & Provenance using JWT" page has a specification that is inconsistent with our other implementations - see https://nhsconnect.github.io/FHIR-NOO-API/development_security_jwt.html for examples.

Additionally, there should be fields to pass in the requesting/setting organisation for audit purposes as the required fields are not available in the FHIR message.