OAUTHaccessTokenUseOpaque

Basic AuditEvent pattern for oAuth Opaque

activeBasic Audit Log Patterns (BALP)1.1.4resource4 key elements

Used when:

  • only have an opaque oAuth token (e.g. clients).
  • have access to the oAuth token, but want to log minimal details.
  • oUser slice holds fragment of the opaque oAuth token

- record only the last 32 characters of the oAuth token to limit risk or replay - presume 32 characters is enough to coorelate AuditEvent log entries

Metadata

hl7.org/fhir
Canonical URL
https://profiles.ihe.net/ITI/BALP/StructureDefinition/IHE.BasicAudit.OAUTHaccessTokenUse.Opaque
ID
IHE.BasicAudit.OAUTHaccessTokenUse.Opaque
Type
Base Definition
Derivation
constraint
Mandatory and Must-Support Elements

Elements with cardinality > 0 or marked as Must Support (S)

PathCard.TypeFlagsDescription
:oUser1..*
1+
other elements may be filled in as needed.
agent.type
1+
agent.policy1..1
S1+
last 32 characters of the oAuth token.
agent.purposeOfUse
S
SAML subject:purposeofuse