Commit af17725
committed
fix(shl): derive the access document per manifest fetch, not once at mint
The completeness fix in 9c9b19b could not reach a single link already in
circulation, and this is why: encryptSHLFile runs at mint, the ciphertext is
stored on the session, and the manifest endpoint replays it verbatim
(`embedded: entry.jwe`). Whatever the document claimed on the day it was created,
it claims forever. A link minted before that fix still tells its recipient
Complete summary — the patient shared their full health record
over a view where the proxy denies all but Patient, ImagingStudy and metadata.
Nothing required the snapshot: the session already holds studyInstanceUID,
shareScope, patientId, sessionToken, expiresAt and the SHL key, so the manifest
can state what is true when asked. It now rebuilds and re-encrypts the document
on each fetch, falling back to the stored blob only if encryption fails — a stale
claim still beats handing the recipient a link that will not open.
Mint and manifest share one buildSmartApiAccess so a fresh link and a later fetch
cannot disagree. `expires_in` is now counted from the request rather than from
mint, where it had been describing a lifetime that started days ago.
Existing links, including the one that prompted this, are corrected as soon as the
backend deploys. No re-share needed.1 parent 3ea80e8 commit af17725
2 files changed
Lines changed: 120 additions & 14 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
92 | 92 | | |
93 | 93 | | |
94 | 94 | | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
95 | 126 | | |
96 | 127 | | |
97 | 128 | | |
| |||
438 | 469 | | |
439 | 470 | | |
440 | 471 | | |
441 | | - | |
442 | | - | |
443 | | - | |
444 | | - | |
445 | | - | |
446 | | - | |
447 | | - | |
448 | | - | |
449 | | - | |
450 | | - | |
451 | | - | |
452 | | - | |
453 | | - | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
454 | 481 | | |
455 | 482 | | |
456 | 483 | | |
| |||
614 | 641 | | |
615 | 642 | | |
616 | 643 | | |
| 644 | + | |
| 645 | + | |
| 646 | + | |
| 647 | + | |
| 648 | + | |
| 649 | + | |
| 650 | + | |
| 651 | + | |
| 652 | + | |
| 653 | + | |
| 654 | + | |
| 655 | + | |
| 656 | + | |
| 657 | + | |
| 658 | + | |
| 659 | + | |
| 660 | + | |
617 | 661 | | |
618 | 662 | | |
619 | 663 | | |
620 | 664 | | |
621 | 665 | | |
622 | | - | |
| 666 | + | |
623 | 667 | | |
624 | 668 | | |
625 | 669 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
0 commit comments