microsoft / microsoft/fhir-server

Restrict which records / rows an API user can access based on the user's affiliation to an organisation.

Open
#1,613 6 comments 0 reactions 0 assignees View on GitHub
Area-Authorization Epic
Dominant language
TSQL
Stars
1.4k
Forks
592
Avg merge
2d 7h
Merged PRs (30d)
41

Description

User story
As an MS FHIR Server admin, I want to be able to restrict which records / rows an API user can access based on the user's affiliation to an organisation.

For example in Patient.managingOrganization (Organization that is the custodian of the patient record), an authenticated API User, with an affiliation to the Patient.managingOrganization that is the custodian of the patient record can only see patient records linked to the Patient.managingOrganization.

Could this be implemented using database policies / row level security in SQL database? A similar concept exists in Oracle virtual private database :- https://docs.oracle.com/cd/B28359_01/network.111/b28531/vpd.htm#DBSEG007

The id of the caller is passed to the database where the database policy adds a dynamic WHERE clause to a SQL statement that is issued against the table, view, or synonym to which the Database security policy was applied.

Acceptance criteria

When an authenticated API User, with an affiliation to the Patient.managingOrganization submits a search request, the database policies / row level security will only return matches which are also linked to the Patient.managingOrganization.
Search matches which are not also linked to the Patient.managingOrganization will not be returned.

Contributor guide

Open the contributing guide

Research direction

No source files, tests, or entry points are named. Start by tracing authenticated API search requests to the database layer and reviewing how Patient.managingOrganization and user affiliations are represented. Done means searches return only records linked to the caller's affiliated organization, while unrelated matches are excluded.

Written by the indexing model from the issue text.

Assessment

Tech stack
sql
Domain
api, authorization, databases
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.