Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

decision to deny is not typically communicated by returning an authorization code #162

Open
lcmaas opened this issue Mar 17, 2018 · 0 comments

Comments

@lcmaas
Copy link

lcmaas commented Mar 17, 2018

The SMART App Launch Framework page currently has this text

"The EHR decides whether to grant or deny access. This decision is communicated to the app when the EHR authorization server returns an authorization code."

Denial would typically be communicated with an "error=access_denied" parameter rather than a "code=xyz" parameter. The current text might be misconstrued to mean a code is always required, even when access is denied, so I suggest that last part of this be changed to something like "The decision to grant access is communicated to the app when the EHR authorization server returns an authorization code. Denial of access is communicated as described in Section 4.1.2.1 of RFC 6749."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant