Yes, that Side-stepping scenario.
The EHR is actually decoupled from the FHIR resources. I’m trying to figure out how Smart on FHIR overlays and I don’t think it does. That side-step flow is more accurate.
EHR user, has an account in the OIDC/Oauth provider, but authentications locally within the EHR from which they want to launch the viewer.
The FHIR resources trust Oauth tokens from the OIDC provider only. Hence why I may have incorrectly labelled it the FHIR authorisation server.
I don’t believe Smart on FHIR address the gap in the chain. – “launch is for the user to permit you to access the external FHIR API on their behalf” that is the bridge needed. Which I conclude is a different flow.
Thanks
Raymond
--
You received this message because you are subscribed to a topic in the Google Groups "SMART on FHIR" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/smart-on-fhir/Wqmre2UWNiY/unsubscribe.
To unsubscribe from this group and all its topics, send an email to smart-on-fhi...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/smart-on-fhir/773c8909-2698-4446-8a1d-258d32853a23n%40googlegroups.com.
This email (including attachments), may contain information which is confidential or subject to copyright. If you are not the intended recipient, please notify us immediately and then delete this email from your system.