{"_id":"@aws/fhir-works-on-aws-authz-smart","_rev":"4-9597c8570c14d1e7634bb4ce7905c577","name":"@aws/fhir-works-on-aws-authz-smart","dist-tags":{"latest":"4.0.1"},"versions":{"3.1.4":{"name":"@aws/fhir-works-on-aws-authz-smart","version":"3.1.4","description":"FHIR Works on AWS SMART on FHIR authorization","homepage":"https://github.com/aws-solutions/fhir-works-on-aws/fwoa-core/authz-smart","repository":{"type":"git","url":"git://github.com/awslabs/fhir-works-on-aws-authz-smart.git"},"license":"Apache-2.0","author":{"name":"Amazon Web Services","email":"fhir-works-on-aws-dev@amazon.com","url":"https://aws.amazon.com/"},"main":"lib/index.js","types":"lib/index.d.ts","resolutions":{"**/@typescript-eslint/eslint-plugin":"^4.1.1","**/@typescript-eslint/parser":"^4.1.1","ansi-regex":"^5.0.1","axios":"^0.21.4","json5":"^2.2.2","jsonwebtoken":"^9.0.0","set-value":"^4.0.1"},"dependencies":{"@aws/fhir-works-on-aws-interface":"12.1.0","axios":"^0.21.4","jsonwebtoken":"^9.0.0","jwks-rsa":"^1.12.1","lodash":"^4.17.21"},"devDependencies":{"@aws/eslint-config-fwoa-eslint-custom":"0.0.1","@rushstack/eslint-config":"^3.0.0","@rushstack/heft":"0.49.0","@rushstack/heft-jest-plugin":"0.4.2","@rushstack/heft-node-rig":"1.11.11","@types/heft-jest":"^1.0.3","@types/jest":"^26.0.19","@types/jsonwebtoken":"^8.5.4","@types/lodash":"^4.14.182","@types/node":"^14","axios-mock-adapter":"^1.18.2","csv-load-sync":"^2.3.1","csv-writer":"^1.6.0","eslint":"^8.7.0","fs":"0.0.1-security","jest":"^26.6.3","jest-mock-extended":"^1.0.8","jose":"^3.5.1","json-2-csv":"^3.17.2","npm-package-json-lint":"^6.3.0","npm-package-json-lint-config-default":"^5.0.0","sort-package-json":"^1.57.0","standard-version":"^9.3.2","ts-jest":"^26.4.4","typescript":"^4.9.4"},"engines":{"node":">=18.0.0"},"scripts":{"build":"heft build --clean && rushx pkg-json-lint","build-test":"heft test --clean && rushx pkg-json-lint","clean":"rm -rf build/* node_modules/* dist/* .nyc_output/* lib/*","lint":"eslint . --ext .ts,.tsx","lint-fix":"eslint --fix . --ext .ts,.tsx","local":"node .","pkg-json-lint":"npmPkgJsonLint -c ../../.npmpackagejsonlintrc.json .","release":"rush build && rush lint-fix && rush test","sort-package-json":"sort-package-json package.json","standard-version":"standard-version --skip.tag=true","test":"heft test --clean --no-build && rushx pkg-json-lint","test-coverage":"jest --coverage","watch":"tsc -w"},"gitHead":"42549579feaa325466353a45c6c7190ca637464e","bugs":{"url":"https://github.com/awslabs/fhir-works-on-aws-authz-smart/issues"},"_id":"@aws/fhir-works-on-aws-authz-smart@3.1.4","_integrity":"sha512-inKlrmsURLmXH3fgwosuKTkq1ZsCyj9YBJegVjih4pUhpkgmKRRfhegQM51lesbG6vVpGR/q42fpnV9Ad1K66A==","_resolved":"/tmp/3fa59d62c211f0d70d8c57cd4eec94fe/aws-fhir-works-on-aws-authz-smart-3.1.4.tgz","_from":"file:aws-fhir-works-on-aws-authz-smart-3.1.4.tgz","_nodeVersion":"18.15.0","_npmVersion":"9.5.0","dist":{"integrity":"sha512-inKlrmsURLmXH3fgwosuKTkq1ZsCyj9YBJegVjih4pUhpkgmKRRfhegQM51lesbG6vVpGR/q42fpnV9Ad1K66A==","shasum":"3b373dbcdd56e3f0be9f2e3957827dcf29218b16","tarball":"https://registry.npmjs.org/@aws/fhir-works-on-aws-authz-smart/-/fhir-works-on-aws-authz-smart-3.1.4.tgz","fileCount":94,"unpackedSize":895195,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAgmkcldRBZnMwaAFgNDtLEMx04Ro9Y2XAnrijqU03ykAiAf2Iapl139P3sWOy5zX2JQ0bBIib4/toSdcLblyyMpnw=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkKuiCACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp13A//VmR0VyT9KdOJe0nZgdHuk1w/yEkphhTBqOTkl/Pdnzptqd2h\r\nAxt5OXAallxVZzexa1DIchbsJsC6e+yEfsRqSgDvwWPhW1iM3A/XcXml6BUB\r\nJNu9DpQIHWhAlYfpyTTTdud+5WNxCkwQnVFnPOotd31y5PXR22TOCbGaT0ki\r\nuVcUXXIRfs2JpR6JsjZpjV6afo/Km3vCC+FDKmcjOHhB+2pqQRSSOEOkuO2Y\r\nMH1AUcGisVvJJknYtoDTRzlFBsSF1DzWcADo1EgJP2vqMdieOF3+8AGZEbj+\r\nryfj9jtB1OIg+7TY/rdVNNpQzrkwiKy4rDXEY0xpLSO1+syAGcPY1ys20nno\r\nNkyr/AsMlzKsOgEcSRLgo42HYujg1rjrIEbJhkfe6s9np174gNshjtqIRKh7\r\n8dtNrT5O8XKQQRH5k3mTkLYfkvN/91HnRZ3uU86TlCnzvnk1dGOUDCS+5Lp/\r\naMio90xXZLMY6o3IH49YAC37WGxX9EkA7NLkEp/9hpqZhnK2HEh2wO0uImzR\r\nlyxgvgDroKMcA9B3SAgiv6jib5Ml17OVnk6Cs6SUiXWxpq+n7Wfeq+ChI+BQ\r\nRPiuwLUOnptXXcRClvF5zIsoz45ZDuETaFa6hSES8FMHfnuAHwesAekYI2em\r\nSkPQ9ovcfmzEtZFnNWDegsQPWw+eh+LQVUk=\r\n=Zo/m\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"wwps-psh-dev","email":"wwps-psh-dev@amazon.com"},"directories":{},"maintainers":[{"name":"wwps-psh-dev","email":"wwps-psh-dev@amazon.com"},{"name":"ma-foundation","email":"mafoundation-team@amazon.com"},{"name":"rsmayda","email":"smayda44@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fhir-works-on-aws-authz-smart_3.1.4_1680533634256_0.5816425358154422"},"_hasShrinkwrap":false,"deprecated":"We are deprecating this npm package. Please use https://www.npmjs.com/package/fhir-works-on-aws-authz-smart instead."},"4.0.0":{"name":"@aws/fhir-works-on-aws-authz-smart","version":"4.0.0","description":"FHIR Works on AWS SMART on FHIR authorization","homepage":"https://github.com/aws-solutions/fhir-works-on-aws","repository":{"type":"git","url":"git+https://github.com/aws-solutions/fhir-works-on-aws.git"},"license":"Apache-2.0","author":{"name":"Amazon Web Services","email":"fhir-works-on-aws-dev@amazon.com","url":"https://aws.amazon.com/"},"main":"lib/index.js","types":"lib/index.d.ts","resolutions":{"**/@typescript-eslint/eslint-plugin":"^4.1.1","**/@typescript-eslint/parser":"^4.1.1","ansi-regex":"^5.0.1","axios":"^0.21.4","json5":"^2.2.2","jsonwebtoken":"^9.0.0","set-value":"^4.0.1"},"dependencies":{"@aws/fhir-works-on-aws-interface":"13.0.0","axios":"^0.21.4","jsonwebtoken":"^9.0.0","jwks-rsa":"^1.12.1","lodash":"^4.17.21"},"devDependencies":{"@aws/eslint-config-fwoa-eslint-custom":"0.0.1","@rushstack/eslint-config":"^3.0.0","@rushstack/heft":"0.49.0","@rushstack/heft-jest-plugin":"0.4.2","@rushstack/heft-node-rig":"1.11.11","@types/heft-jest":"^1.0.3","@types/jest":"^26.0.19","@types/jsonwebtoken":"^8.5.4","@types/lodash":"^4.14.182","@types/node":"^14","axios-mock-adapter":"^1.18.2","csv-load-sync":"^2.3.1","csv-writer":"^1.6.0","eslint":"^8.7.0","fs":"0.0.1-security","jest":"^26.6.3","jest-mock-extended":"^1.0.8","jose":"^3.5.1","json-2-csv":"^3.17.2","npm-package-json-lint":"^6.3.0","npm-package-json-lint-config-default":"^5.0.0","sort-package-json":"^1.57.0","standard-version":"^9.3.2","ts-jest":"^26.4.4","typescript":"^4.9.4"},"engines":{"node":">=18.0.0"},"scripts":{"build":"heft build --clean && rushx pkg-json-lint","build-test":"heft test --clean && rushx pkg-json-lint","clean":"rm -rf build/* node_modules/* dist/* .nyc_output/* lib/*","lint":"eslint . --ext .ts,.tsx","lint-fix":"eslint --fix . --ext .ts,.tsx","local":"node .","pkg-json-lint":"npmPkgJsonLint -c ../../.npmpackagejsonlintrc.json .","release":"rush build && rush lint-fix && rush test","sort-package-json":"sort-package-json package.json","standard-version":"standard-version --skip.tag=true","test":"heft test --clean --no-build && rushx pkg-json-lint","test-coverage":"jest --coverage","watch":"tsc -w"},"gitHead":"928dc2816b6d363c408886ea3f6ce02348f19ebc","bugs":{"url":"https://github.com/aws-solutions/fhir-works-on-aws/issues"},"_id":"@aws/fhir-works-on-aws-authz-smart@4.0.0","_integrity":"sha512-sLhMVSeSRna72ES2ZvH6abv4n0+ToCBxZbevf1u3q6SctRwYfUw/UN6eBiQB6S55AQF7K/tWLGxvpjso0tuOpA==","_resolved":"/tmp/3f112a56d62b8a653ca775a1b823beff/aws-fhir-works-on-aws-authz-smart-4.0.0.tgz","_from":"file:aws-fhir-works-on-aws-authz-smart-4.0.0.tgz","_nodeVersion":"18.15.0","_npmVersion":"9.5.0","dist":{"integrity":"sha512-sLhMVSeSRna72ES2ZvH6abv4n0+ToCBxZbevf1u3q6SctRwYfUw/UN6eBiQB6S55AQF7K/tWLGxvpjso0tuOpA==","shasum":"42dc243727081464e4dfe4f57119cc94df4b154d","tarball":"https://registry.npmjs.org/@aws/fhir-works-on-aws-authz-smart/-/fhir-works-on-aws-authz-smart-4.0.0.tgz","fileCount":94,"unpackedSize":896774,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHcsg8v4+1QzhcO9qlJHPDHReCYAMv1W0W67x0srWkShAiEAqSrqaK1Y3uziIiDoRYEU8nIiDimQ/KLLWdgHKxbeL/8="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkK0N+ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqyNQ//dPoItluiEXxLHKkEG4N9aSPDdSaqvbKR+2KRX57EOCILA19l\r\n+u5Vv4C97uSP/fGCf9n90v0gxd6+Mbq7HQX6fuCXtzyWGZX0NN0ylQPIZhTB\r\nSEMyCEyM+V5K46muk1211Bi4msO964TGc1h0e8ydrAUU5Zq6CDze2uG4L5Q2\r\naCnVHWvDZceI1+MvM2QYyb+6hk/liU6zfWnJBtfPmHiA+4+5c5wVfFS7mG8F\r\npoQAaWCGkPfgfQjOuEFYaLwN/TnnNJk2t/Jr/VGW4wsJDjLstak0umRvkHUt\r\nS36qbmWXTcX+FJvqL78E46v+mFHwqiSlOd1XDhBGiphYvzM3kCGo025CU8T7\r\nO+52YZQ4cYg2+9TUNO8Xi/uWOT9dZazLeYdXiC3BwOA9SNIcD9p6JsBbhyaB\r\nRCWxFO9gnlm5QMJsLPirB3agkukYSDNBcMEBX34T1LmtNEk505VC/5cos7QU\r\nUmzHSVeS9dC9PUKpybWwaWS0r6B0K7G/VbtYcRhRxbjC0tSWqtgLdEPu4kvB\r\n1w8iknDk9iCyt2rDTbALFu4rL0oQlZn8ap0rbnIIS7ohzJeju90eKq0YOv8S\r\ndqCtofUgLAtMJhhHnD8BmDRcAGQ1FloIG0WCnHYiyiYlmpUyqw4595X+fhTp\r\nse+QFIqgUMfGj1IBCA3dfc8H2rO0M7HLA+s=\r\n=FWgr\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"wwps-psh-dev","email":"wwps-psh-dev@amazon.com"},"directories":{},"maintainers":[{"name":"wwps-psh-dev","email":"wwps-psh-dev@amazon.com"},{"name":"ma-foundation","email":"mafoundation-team@amazon.com"},{"name":"rsmayda","email":"smayda44@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fhir-works-on-aws-authz-smart_4.0.0_1680556926427_0.0370160501503054"},"_hasShrinkwrap":false,"deprecated":"We are deprecating this npm package. Please use https://www.npmjs.com/package/fhir-works-on-aws-authz-smart instead."},"4.0.1":{"name":"@aws/fhir-works-on-aws-authz-smart","version":"4.0.1","description":"FHIR Works on AWS SMART on FHIR authorization","homepage":"https://github.com/aws-solutions/fhir-works-on-aws","repository":{"type":"git","url":"git+https://github.com/aws-solutions/fhir-works-on-aws.git"},"license":"Apache-2.0","author":{"name":"Amazon Web Services","email":"fhir-works-on-aws-dev@amazon.com","url":"https://aws.amazon.com/solutions"},"main":"lib/index.js","types":"lib/index.d.ts","resolutions":{"**/@typescript-eslint/eslint-plugin":"^4.1.1","**/@typescript-eslint/parser":"^4.1.1","ansi-regex":"^5.0.1","axios":"^0.21.4","json5":"^2.2.2","jsonwebtoken":"^9.0.0","set-value":"^4.0.1"},"dependencies":{"@aws/fhir-works-on-aws-interface":"13.0.1","axios":"^0.21.4","jsonwebtoken":"^9.0.0","jwks-rsa":"^1.12.1","lodash":"^4.17.21"},"devDependencies":{"@aws/eslint-config-fwoa-eslint-custom":"0.0.1","@rushstack/eslint-config":"^3.0.0","@rushstack/heft":"0.49.0","@rushstack/heft-jest-plugin":"0.4.2","@rushstack/heft-node-rig":"1.11.11","@types/heft-jest":"^1.0.3","@types/jest":"^26.0.19","@types/jsonwebtoken":"^8.5.4","@types/lodash":"^4.14.182","@types/node":"^14","axios-mock-adapter":"^1.18.2","csv-load-sync":"^2.3.1","csv-writer":"^1.6.0","eslint":"^8.7.0","fs":"0.0.1-security","jest":"^26.6.3","jest-mock-extended":"^1.0.8","jose":"^3.5.1","json-2-csv":"^3.17.2","npm-package-json-lint":"^6.3.0","npm-package-json-lint-config-default":"^5.0.0","sort-package-json":"^1.57.0","standard-version":"^9.3.2","ts-jest":"^26.4.4","typescript":"^4.9.4"},"engines":{"node":">=18.0.0"},"scripts":{"build":"heft build --clean && rushx pkg-json-lint","build-test":"heft test --clean && rushx pkg-json-lint","clean":"rm -rf build/* node_modules/* dist/* .nyc_output/* lib/*","lint":"eslint . --ext .ts,.tsx","lint-fix":"eslint --fix . --ext .ts,.tsx","local":"node .","pkg-json-lint":"npmPkgJsonLint -c ../../.npmpackagejsonlintrc.json .","release":"rush build && rush lint-fix && rush test","sort-package-json":"sort-package-json package.json","standard-version":"standard-version --skip.tag=true","test":"heft test --clean --no-build && rushx pkg-json-lint","test-coverage":"jest --coverage","watch":"tsc -w"},"gitHead":"f5e7d90e843cc86f99e47acee2c8ec872c9b3a65","bugs":{"url":"https://github.com/aws-solutions/fhir-works-on-aws/issues"},"_id":"@aws/fhir-works-on-aws-authz-smart@4.0.1","_integrity":"sha512-8pt/kXEc4srNXxp29Zj1KOTwTEbJbp1wpF3k42mpxyDzQ7LBwbsCdulnwaUSEh12BkE+AB+DToYo/qS0JL0NVQ==","_resolved":"/tmp/0bdbb9240db25f8decbbeb45c337603c/aws-fhir-works-on-aws-authz-smart-4.0.1.tgz","_from":"file:aws-fhir-works-on-aws-authz-smart-4.0.1.tgz","_nodeVersion":"18.15.0","_npmVersion":"9.5.0","dist":{"integrity":"sha512-8pt/kXEc4srNXxp29Zj1KOTwTEbJbp1wpF3k42mpxyDzQ7LBwbsCdulnwaUSEh12BkE+AB+DToYo/qS0JL0NVQ==","shasum":"1345267bede48ed0c4e7b8db2d0b0ad5969b4345","tarball":"https://registry.npmjs.org/@aws/fhir-works-on-aws-authz-smart/-/fhir-works-on-aws-authz-smart-4.0.1.tgz","fileCount":94,"unpackedSize":899230,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDmZ4cNGLQBioo8ESm+yyj+btInmep69wbbvAPfql4GTAIgUFXlWXebF2Etf2G8yNeECrPqFOf9cC09d4A2F78D/DE="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkOBMWACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpgYw/+K1NW3HoSHHvTa9Nvx2sMFAYqaRzZnCc4y5ruz5Gl2pQBUD60\r\n7+y3PCy7shiChXJeRvf5kQUoxYkyocYGEEExIztBb6OsJhiD4Pwde19IUNCL\r\nt2ofvUrAfEdkNmgOv0rXWUFR87aRcKHQ8DLtPe72fLCgXHqLERCHjXqMtlA1\r\n7W29aaQuEJem1quQrNo+zLP6yi6dtKBC+uGNB+ITceIOvRNzjIHTzqIGIfMD\r\nF+FkxhUJvpULCxHqj5I93q5iOVExEb0leB8VIqb70sCEO65gP+CKvEfa4JYp\r\nZ4bbNC0/M/QcIsjonWeDkNf4H9b01ukqieuWNaH560uUn+bGQJ3sPM4chDux\r\nUwVfjvOkarGj3ocMF29yx6ZxRIQx8oSjMgzuhMZLmgJt6ANzPZpCnFgZUghb\r\ndlRmZnT+IxJIDCOhASr1Wyv4lje77+LyXsZvQUHXZ5KUssaPxroTAmDpt8Pc\r\nqPXtFDOIH/h3ZeLYX97VcR44u9PP8Mmi2Ssf0wY0tCOApIAglB9rxnjnd+WH\r\n4bjRGQ/HGwekwi2w8i5tiuaTbBgAshI1yCTsDRqYyb+vJ82MbTanyELWqF7y\r\n4QdCKeeED5aGWX/ek18Krzri+5zSoQ8bX8PU4TxD0qDfpgjB7NbRoC9+wxyA\r\nU70iHEgIwCm4aKKCa6UX0rJJNKYcO5LlaSs=\r\n=K0qn\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"wwps-psh-dev","email":"wwps-psh-dev@amazon.com"},"directories":{},"maintainers":[{"name":"wwps-psh-dev","email":"wwps-psh-dev@amazon.com"},{"name":"ma-foundation","email":"mafoundation-team@amazon.com"},{"name":"rsmayda","email":"smayda44@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/fhir-works-on-aws-authz-smart_4.0.1_1681396502106_0.21504411197035878"},"_hasShrinkwrap":false,"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."}},"time":{"created":"2023-04-03T14:53:54.188Z","3.1.4":"2023-04-03T14:53:54.714Z","modified":"2024-01-31T16:12:18.708Z","4.0.0":"2023-04-03T21:22:06.619Z","4.0.1":"2023-04-13T14:35:02.393Z"},"maintainers":[{"name":"ma-foundation","email":"mafoundation-team@amazon.com"},{"name":"rsmayda","email":"smayda44@gmail.com"},{"name":"wwps-psh-dev","email":"wwps-psh-dev@amazon.com"}],"description":"FHIR Works on AWS SMART on FHIR authorization","homepage":"https://github.com/aws-solutions/fhir-works-on-aws","repository":{"type":"git","url":"git+https://github.com/aws-solutions/fhir-works-on-aws.git"},"author":{"name":"Amazon Web Services","email":"fhir-works-on-aws-dev@amazon.com","url":"https://aws.amazon.com/solutions"},"bugs":{"url":"https://github.com/aws-solutions/fhir-works-on-aws/issues"},"license":"Apache-2.0","readme":"# fhir-works-on-aws-authz-smart\n\n## Upgrade notice\n\nVersions 3.1.1 and 3.1.2 of the `fhir-works-on-aws-authz-smart` package have been deprecated for necessary security updates. Please upgrade to version 3.1.3 or higher. For more information, see [the fhir-works-on-aws-authz-smart security advisory](https://github.com/awslabs/fhir-works-on-aws-authz-smart/security/advisories/GHSA-vv7x-7w4m-q72f).\n\n## Purpose\n\nThis package is an implementation of the authorization interface from the [FHIR Works interface](https://github.com/awslabs/fhir-works-on-aws-interface/blob/mainline/src/authorization.ts). It uses the [Substitutable Medical Applications, Reusable Technologies (SMART on FHIR) specification v1.0.0](http://www.hl7.org/fhir/smart-app-launch/1.0.0) to authorize users. Requests are authorized if the requestor or the patient in context is [**referenced**](https://www.hl7.org/fhir/references.html) in the resource in question.\n\nTo use and deploy this component please follow the overall [`smart-mainline` branch README](https://github.com/awslabs/fhir-works-on-aws-deployment/tree/smart-mainline)\n\n## Assumptions\n\nThe following assumptions have been made while creating this package:\n\n- An [OAuth2](https://oauth.net/2/) [OpenID Connect](https://openid.net/connect/) authorization server already exists and is used as, or in conjunction with, an identity provider.\n  - The OAuth2 server complies with the [SMART on FHIR specification](https://docs.smarthealthit.org/)\n  - The OAuth2 server has a JSON Web Key Set endpoint used to get the key for verifying incoming access tokens\n- The identity provider has a user claim (either `fhirUser` or `profile`) representing who this user is in context to this FHIR server. This user must be represented by a fully qualified URL in the claim.\n  - As an example, the `fhirUser` claim should look like: `https://www.fhir.com/Patient/1234`\n  - When using `user` scopes it is assumed that the `fhirUser` will be in the access token to determine who the requestor is\n- [`launch` scopes and contextual request](http://www.hl7.org/fhir/smart-app-launch/1.0.0/scopes-and-launch-context/#scopes-for-requesting-context-data) will be handled by the authorization server.\n- Once launch context is given to the authorization server it will be included with a `patient` scope and the Patient's resourceType and id in the `launch_response_patient` claim within the access token.\n  - As an example, the `launch_response_patient` claim should look like: `Patient/id`\n\n## Authorization\n\nThis packages uses SMART scopes and the references found in the resources as a way to determine access. Scopes are used to tell the authorization and resource server what access the requestor has. In addition, the references are used to do further authorization, in an attribute based access control model.\n\n### Scopes\n\nThis resource server supports [SMART' v1.0.0 clinical scopes](http://www.hl7.org/fhir/smart-app-launch/1.0.0/scopes-and-launch-context/#scopes-for-requesting-clinical-data). There are some assumptions made on the authorization and resource server relationship:\n\n- For `patient` scopes, there must be a `launch_response_patient` claim in the access token. The access token with `patient` scopes but no `launch_response_patient` claim will be rejected.\n- For `user` scopes, there must be a `fhirUser` claim in the access token. The access token with `user` scopes but no `fhirUser` claim will be rejected.\n- The access modifiers `read` and `write` will give permissions as defined in the incoming [SMARTConfig](./src/smartConfig.ts).\n\nThe resource server also supports [SMART's Flat FHIR or Bulk Data `system` scope](https://hl7.org/fhir/uv/bulkdata/authorization/index.html#scopes). `system` scopes have the format `system/(:resourceType|*).(read|write|*)`– which conveys the same access scope as the matching user format `user/(:resourceType|*).(read|write|*)`.\n\n### Attribute Based Access Control (ABAC)\n\nThis implementation of the SMART on FHIR specification uses attribute based access control. Access to a resource is given if one of the following statements is true:\n\n- The fhirUser making the request is considered an Admin (default configuration makes a Practitioner an admin).\n- The fhirUser making the request or the patient in context is looking up their own resource (verified via the `resourceType` and `id`).\n- The fhirUser making the request or the patient in context is referenced in the resource in which they are taking action on.\n\nAs an example below, the Patient resource is accessible by:\n\n- Admins of the system\n- Requests with the usage of the `system` scope\n- `Patient/example`: via `resourceType` and `id` check\n- `Patient/diffPatient`: because it is referenced in the `link` field\n- `Practitioner/DrBell`: because it is referenced in the `generalPractitioner` field\n\n```json\n// Example Patient resource with references\n{\n  \"resourceType\": \"Patient\",\n  \"id\": \"example\",\n  \"generalPractitioner\": [\n    {\n      \"reference\": \"Practitioner/DrBell\"\n    }\n  ],\n  \"link\": [\n    {\n      \"type\": \"seealso\",\n      \"other\": {\n        \"reference\": \"Patient/diffPatient\"\n      }\n    }\n  ],\n  \"address\": [\n    {\n      \"period\": {\n        \"start\": \"1974-12-25\"\n      },\n      \"city\": \"London\",\n      \"use\": \"home\",\n      \"line\": [\"221b Baker St\"],\n      \"district\": \"Marylebone\",\n      \"postalCode\": \"6XE\",\n      \"text\": \"221b Baker St, Marylebone, London NW1 6XE, United Kingdom\",\n      \"type\": \"both\"\n    }\n  ],\n  \"deceasedBoolean\": false,\n  \"name\": [\n    {\n      \"family\": \"Holmes\",\n      \"given\": [\"Sherlock\"],\n      \"use\": \"official\"\n    }\n  ],\n  \"gender\": \"male\",\n  \"active\": true\n}\n```\n\n## Usage\n\nAdd this package to your `package.json` file and install as a dependency. For usage examples please see the deployment component's [package.json](https://github.com/awslabs/fhir-works-on-aws-deployment/blob/smart-mainline/package.json)\n\n### Configuration\n\nThe SMART specification gives a lot of room for interpretation between the resource and authorization server relationship. With this in mind we developed our SMART implementation to be flexible. The configurations currently available can be viewed in the [SMARTConfig](./src/smartConfig.ts).\n\n### SMART on FHIR scope rules\n\nWithin the [SMARTConfig](./src/smartConfig.ts) you can see an example implementation of a ScopeRule. The ScopeRule says which operations a scope gives access to. For example, the `user/*.write` scope provides access to 'create' resource but not 'update' resource.\n\nFor an example usage of the SMARTConfig, please see [authZConfig.ts](https://github.com/awslabs/fhir-works-on-aws-deployment/blob/smart-mainline/src/authZConfig.ts) in the deployment package.\n\n## Dependency tree\n\nThis package is dependent on:\n\n- [interface component](https://github.com/awslabs/fhir-works-on-aws-interface)\n  - This package defines the interface we are trying to use\n\n## Known issues\n\nYou can track the issues on the GitHub repository.\n\n## Security\n\nSee [CONTRIBUTING](CONTRIBUTING.md#security-issue-notifications) for more information.\n\n## License\n\nThis project is licensed under the Apache-2.0 License.\n","readmeFilename":"README.md"}