FHIR Chat · fhircast-docs / PR #334 Stu2 subscription updates · fhircast-github

Stream: fhircast-github

Topic: fhircast-docs / PR #334 Stu2 subscription updates


view this post on Zulip Github Notifications (FHIRcast) (Oct 21 2020 at 12:43):

NiklasSvenzen opened PR #334 from STU2-SubscriptionUpdates to master:

FHIR-25653 - No intent verification for Unsubscriptions
FHIR-25824 - Optionality for websockets vs. webhooks clarified
FHIR-25834 - Unsubscription text cleanup
FHIR-25835 - Optionality for websockets vs. webhooks clarified even more
FHIR-25832 - Close web socket on lease_seconds expiration

view this post on Zulip Github Notifications (FHIRcast) (Oct 21 2020 at 12:43):

NiklasSvenzen requested isaacvetter for a review on PR #334.

view this post on Zulip Github Notifications (FHIRcast) (Oct 21 2020 at 12:43):

NiklasSvenzen requested wmaethner for a review on PR #334.

view this post on Zulip Github Notifications (FHIRcast) (Oct 26 2020 at 16:52):

isaacvetter requested isaacvetter and wmaethner for a review on PR #334.

view this post on Zulip Github Notifications (FHIRcast) (Oct 26 2020 at 16:52):

isaacvetter submitted PR Review.

view this post on Zulip Github Notifications (FHIRcast) (Oct 26 2020 at 21:33):

wmaethner submitted PR Review.

view this post on Zulip Github Notifications (FHIRcast) (Oct 26 2020 at 21:33):

wmaethner created PR Review Comment:

Shoudl add a period at the end of this paragraph.

view this post on Zulip Github Notifications (FHIRcast) (Oct 26 2020 at 21:34):

wmaethner edited PR Review Comment.

view this post on Zulip Github Notifications (FHIRcast) (Oct 26 2020 at 21:43):

isaacvetter submitted PR Review.

view this post on Zulip Github Notifications (FHIRcast) (Oct 26 2020 at 21:43):

isaacvetter created PR Review Comment:

In order to prevent an attacker from creating unwanted subscriptions on behalf of a subscriber, a Hub must ensure that a `webhook` subscriber did indeed send the subscription request. The Hub SHALL verify a subscription request by sending an HTTPS GET request to the subscriber's callback URL as given in the subscription request. This request SHALL have the following query string arguments appended.

view this post on Zulip Github Notifications (FHIRcast) (Oct 26 2020 at 21:44):

isaacvetter updated PR #334 from STU2-SubscriptionUpdates to master:

FHIR-25653 - No intent verification for Unsubscriptions
FHIR-25824 - Optionality for websockets vs. webhooks clarified
FHIR-25834 - Unsubscription text cleanup
FHIR-25835 - Optionality for websockets vs. webhooks clarified even more
FHIR-25832 - Close web socket on lease_seconds expiration

view this post on Zulip Github Notifications (FHIRcast) (Oct 27 2020 at 12:51):

NiklasSvenzen merged PR #334.


Last updated: Apr 12 2022 at 19:14 UTC